
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21986 is a Denial of Service vulnerability in the Core component of Oracle VM VirtualBox, affecting versions 7.1.14 and 7.2.4. It was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026. The vulnerability is restricted to Windows VMs only and allows an unauthenticated local attacker to cause a complete hang or frequently repeatable crash of VirtualBox, with scope change implications affecting additional products. It carries a CVSS v3.1 base score of 7.1 (High) (Oracle CPU Jan 2026).
The vulnerability resides in the Core component of Oracle VM VirtualBox and is classified as a Denial of Service flaw (CWE category: availability impact). An unauthenticated attacker with local logon access to the infrastructure where VirtualBox executes can trigger the vulnerability without requiring any privileges or user interaction (PR:N, UI:N). The scope change (S:C) indicates that a successful attack can impact resources beyond VirtualBox itself, potentially affecting the host or other co-located VMs. The vulnerability is noted to apply exclusively to Windows VMs. The researcher credited with discovery is Mohammed Ba Rashed (Oracle CPU Jan 2026). A public proof-of-concept repository (CVE-2026-21986-VirtualBox-DoS) appeared on GitHub in mid-2026, though its reliability and completeness are unconfirmed.
Successful exploitation results in a complete Denial of Service — specifically, a hang or frequently repeatable crash of Oracle VM VirtualBox — affecting availability with no impact on confidentiality or integrity. Because the scope is marked as changed, the disruption may extend beyond the VirtualBox process itself to affect other products or VMs running on the same infrastructure. The impact is limited to Windows VM guests; non-Windows VM configurations are not affected (Oracle CPU Jan 2026).
VBox.log in the VM's snapshot directory) showing abnormal termination events or assertion failures; Windows Event Logs recording application crashes for VirtualBoxVM.exe or VBoxSVC.exe..dmp) in the system or user temp directories on the host running Windows VMs.Oracle has released patches for CVE-2026-21986 as part of the January 2026 Critical Patch Update; users should upgrade Oracle VM VirtualBox to a version newer than 7.1.14 (7.1.x branch) and 7.2.4 (7.2.x branch). As a temporary workaround, restrict local logon access to the VirtualBox host infrastructure to trusted and authorized users only, reducing the attack surface. Oracle strongly recommends applying CPU patches without delay rather than relying on access restrictions as a long-term solution (Oracle CPU Jan 2026).
The vulnerability received routine coverage from automated security feeds and aggregators such as RedPacketSecurity (Mastodon) and CVE tracking services shortly after the January 2026 CPU release. No notable independent researcher commentary or significant media coverage specific to this CVE has been identified beyond standard advisory republication. Red Hat also acknowledged the CVE in their security tracking (Oracle CPU Jan 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."