ThreatCluster

Multiple Vulnerabilities Discovered in Oracle VirtualBox

First seen 9 Sep 2026, 22:43 UTC Zerodayinitiativewww.cve.org 46

Article Content

Browse articles
ThreatCluster

A series of vulnerabilities affecting Oracle VirtualBox have been disclosed, allowing local attackers to escalate privileges or disclose sensitive information. The vulnerabilities, identified as ZDI-26-639, ZDI-26-640, ZDI-26-641, ZDI-26-642, ZDI-26-643, and ZDI-26-644, require attackers to execute high-privileged code on the target guest system. The flaws primarily involve improper validation of user-supplied data and lack of memory initialization or locking. Oracle has released updates to address these vulnerabilities. The vulnerabilities were reported to the vendor between June and July 2026, with public advisories released on September 9, 2026. Security professionals are advised to apply the updates promptly to mitigate risks.

Key Points: • Six vulnerabilities in Oracle VirtualBox disclosed, affecting local installations. • Attackers need high-privileged code execution on the guest system to exploit these flaws. • Oracle has issued patches for all identified vulnerabilities as of September 9, 2026.

Ask AI about this cluster

Timeline

2026-06-25
ZDI-26-644 reported
Vulnerability reported to Oracle, affecting the VMSVGA device in VirtualBox.
Zerodayinitiative
2026-07-07
ZDI-26-642 reported
Vulnerability reported to Oracle, affecting the IDisplay component in VirtualBox.
Zerodayinitiative
2026-07-10
ZDI-26-639 reported
Vulnerability reported to Oracle, affecting the VMSVGA device in VirtualBox.
Zerodayinitiative
2026-07-24
ZDI-26-640 and ZDI-26-641 reported
Two vulnerabilities reported to Oracle, affecting VirtioSCSI devices in VirtualBox.
Zerodayinitiative
2026-09-09
Public advisories released
Oracle released advisories for all six vulnerabilities, urging users to apply patches.
Zerodayinitiative