
[ZDI-26-098|CVE-2026-21955] Oracle VirtualBox VMSVGA Use-After-Free Local Privilege Escalation Vulnerability (CVSS 8.2; Credit: VMBreakers(GANGMIN KIM, SANGBIN KIM, Un3xploitable)) https://www.zerodayinitiative.com/advisories/ZDI-26-098/
Post summary
A zero‑day advisory for CVE‑2026‑21955 in Oracle VirtualBox describes a use‑after‑free local privilege escalation vulnerability with CVSS 8.2, but no PoC, exploit code, patch, or active exploitation details are provided.


