
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21956 is an Uncontrolled Resource Consumption (CWE-400) vulnerability in the Core component of Oracle VM VirtualBox, affecting versions 7.1.14 and 7.2.4. It was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026. The vulnerability allows a high-privileged local attacker to fully compromise the VirtualBox hypervisor, with a scope change that may impact additional products. It carries a CVSS v3.1 base score of 8.2 (High) (Oracle CPU Jan 2026). The vulnerability was reported by VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative (Oracle CPU Jan 2026).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and resides in the Core component of Oracle VM VirtualBox. An attacker with high privileges and local logon access to the host infrastructure where VirtualBox executes can exploit this flaw without any user interaction. The attack complexity is low, and successful exploitation results in a scope change — meaning the impact extends beyond VirtualBox itself to potentially affect guest virtual machines and other co-hosted products. A proof-of-concept advisory was published by the Zero Day Initiative (ZDI-26-103) on February 13, 2026 (ZDI Advisory).
Successful exploitation grants the attacker complete takeover of Oracle VM VirtualBox, with high impacts to confidentiality, integrity, and availability. An attacker can access guest virtual machines, modify hypervisor behavior, and disrupt all virtualized systems running on the affected host. The scope change means that compromise of the hypervisor can cascade to additional products and workloads hosted within the virtualized environment (Oracle CPU Jan 2026).
VBoxManage --version).VBoxSVC, VBoxHeadless, VirtualBox) without corresponding guest VM activity.VBox.log) showing abnormal Core component errors, crashes, or resource exhaustion messages; system logs indicating OOM (out-of-memory) events tied to VirtualBox processes..vbox files) or VM disk images; new or altered files in the VirtualBox installation directory.Oracle has released patches for this vulnerability as part of the January 2026 Critical Patch Update; users should upgrade Oracle VM VirtualBox beyond versions 7.1.14 and 7.2.4 to the patched releases provided in the CPU (Oracle CPU Jan 2026). As an interim measure, restrict logon access to the VirtualBox host infrastructure to only trusted and necessary administrators. Implement host-level access controls and monitor for unauthorized administrative activity on systems running VirtualBox. Oracle strongly recommends applying CPU patches without delay rather than relying on workarounds.
The vulnerability received attention from security aggregators and social media shortly after disclosure, with posts on Mastodon (TheHackerWire, RedPacketSecurity) and Bluesky noting the Oracle CPU January 2026 release. Greenbone published a January 2026 threat report covering this and related VirtualBox vulnerabilities. The Zero Day Initiative published a dedicated advisory (ZDI-26-103) in February 2026, providing additional technical context (ZDI Advisory). No major vendor disputes or exceptional community controversy have been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."