CVE-2026-21955PoC(oracle / vm_virtualbox)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for oracle vm_virtualbox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vm_virtualbox

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-16)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
vm_virtualbox

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-13: 1Mentions · 2026-02-17: 1Mentions · 2026-07-16: 2PoC Mentioned / Linked · 2026-07-16: 2Exploit Tool / Code · 2026-07-16: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-17: 1Technical Details · 2026-07-16: 202-1302-1707-16
Signal classification3 categories
PoC
250.0%
General
125.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-131
General1
2026-02-171
Disclosure1
2026-07-162
PoC2
Full discourse4 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-098|CVE-2026-21955] Oracle VirtualBox VMSVGA Use-After-Free Local Privilege Escalation Vulnerability (CVSS 8.2; Credit: VMBreakers(GANGMIN KIM, SANGBIN KIM, Un3xploitable)) https://www.zerodayinitiative.com/advisories/ZDI-26-098/

    Post summary

    A zero‑day advisory for CVE‑2026‑21955 in Oracle VirtualBox describes a use‑after‑free local privilege escalation vulnerability with CVSS 8.2, but no PoC, exploit code, patch, or active exploitation details are provided.

    010931.2K
    5.3K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-21955 PT ID: PT-2026-3703 Vendor: Oracle Corporation Product: Oracle VM VirtualBox Description: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-3703 • https://github.com/minq0x1412/CVE-2026-21955 #dbugs_vuln

    Post summary

    A PoC and exploit for CVE-2026-21955 targeting Oracle VM VirtualBox 7.1.14 and 7.2.4 have been published, with no evidence of active exploitation or available patches.

    02020831
    2.5K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-21955 PT ID: PT-2026-3703 Vendor: Oracle Corporation Product: Oracle VM VirtualBox Description: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-3703 • https://github.com/minq0x1412/CVE-2026-21955 #dbugs_vuln

    Post summary

    A PoC/exploit for CVE‑2026‑21955 in Oracle VM VirtualBox has been released with code links, yet no active exploitation or patching is reported.

    00011881
    2.5K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    General

    Oracle VirtualBox VMSVGA Use-After-Free Local Privilege Escalation Vulnerability (CVE-2026-21955) #CVE202621955 #CyberSecurity #OracleVirtualBox #PrivilegeEscalationVulnerability https://www.systemtek.co.uk/?p=48375 https://t.co/vGmwM2WTm2

    Post summary

    The tweet announces CVE‑2026‑21955 as a VMSVGA use‑after‑free local privilege escalation bug in Oracle VirtualBox, linking to an external site but providing no detail on exploitation, patching, or active attacks.

    0000036
    1.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclevm_virtualbox7.1.14--
Apporaclevm_virtualbox7.2.4--

Explore more