CVE-2026-21986
VirtualBox vulnerability analysis and mitigation

Overview

CVE-2026-21986 is a Denial of Service vulnerability in the Core component of Oracle VM VirtualBox, affecting versions 7.1.14 and 7.2.4. It was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026. The vulnerability is restricted to Windows VMs only and allows an unauthenticated local attacker to cause a complete hang or frequently repeatable crash of VirtualBox, with scope change implications affecting additional products. It carries a CVSS v3.1 base score of 7.1 (High) (Oracle CPU Jan 2026).

Technical details

The vulnerability resides in the Core component of Oracle VM VirtualBox and is classified as a Denial of Service flaw (CWE category: availability impact). An unauthenticated attacker with local logon access to the infrastructure where VirtualBox executes can trigger the vulnerability without requiring any privileges or user interaction (PR:N, UI:N). The scope change (S:C) indicates that a successful attack can impact resources beyond VirtualBox itself, potentially affecting the host or other co-located VMs. The vulnerability is noted to apply exclusively to Windows VMs. The researcher credited with discovery is Mohammed Ba Rashed (Oracle CPU Jan 2026). A public proof-of-concept repository (CVE-2026-21986-VirtualBox-DoS) appeared on GitHub in mid-2026, though its reliability and completeness are unconfirmed.

Impact

Successful exploitation results in a complete Denial of Service — specifically, a hang or frequently repeatable crash of Oracle VM VirtualBox — affecting availability with no impact on confidentiality or integrity. Because the scope is marked as changed, the disruption may extend beyond the VirtualBox process itself to affect other products or VMs running on the same infrastructure. The impact is limited to Windows VM guests; non-Windows VM configurations are not affected (Oracle CPU Jan 2026).

Exploitation steps

  1. Reconnaissance: Identify systems running Oracle VM VirtualBox versions 7.1.14 or 7.2.4 with Windows VMs active, using local system enumeration or asset inventory tools.
  2. Gain local access: Obtain local logon access to the host infrastructure where VirtualBox is running — no credentials or elevated privileges are required beyond basic local logon.
  3. Trigger the vulnerability: Interact with the VirtualBox Core component in a manner that triggers the DoS condition (specific payload details are not publicly confirmed beyond the GitHub PoC repository).
  4. Achieve DoS: The VirtualBox process enters a hang state or crashes repeatedly, causing complete unavailability of the virtualization platform and potentially impacting other products in scope (Oracle CPU Jan 2026).

Indicators of compromise

  • Process: Unexpected VirtualBox process crashes or unresponsive VirtualBox GUI/service on Windows VM hosts; repeated VirtualBox process restarts in a short timeframe.
  • Logs: VirtualBox log files (e.g., VBox.log in the VM's snapshot directory) showing abnormal termination events or assertion failures; Windows Event Logs recording application crashes for VirtualBoxVM.exe or VBoxSVC.exe.
  • System: Increased frequency of VirtualBox-related crash dump files (.dmp) in the system or user temp directories on the host running Windows VMs.

Mitigation and workarounds

Oracle has released patches for CVE-2026-21986 as part of the January 2026 Critical Patch Update; users should upgrade Oracle VM VirtualBox to a version newer than 7.1.14 (7.1.x branch) and 7.2.4 (7.2.x branch). As a temporary workaround, restrict local logon access to the VirtualBox host infrastructure to trusted and authorized users only, reducing the attack surface. Oracle strongly recommends applying CPU patches without delay rather than relying on access restrictions as a long-term solution (Oracle CPU Jan 2026).

Community reactions

The vulnerability received routine coverage from automated security feeds and aggregators such as RedPacketSecurity (Mastodon) and CVE tracking services shortly after the January 2026 CPU release. No notable independent researcher commentary or significant media coverage specific to this CVE has been identified beyond standard advisory republication. Red Hat also acknowledged the CVE in their security tracking (Oracle CPU Jan 2026).

Additional resources


SourceThis report was generated using AI

Related VirtualBox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60159HIGH7.5
  • VirtualBox logoVirtualBox
  • virtualbox
NoNoJul 21, 2026
CVE-2026-60158MEDIUM6.4
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60162MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60161MEDIUM6.1
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026
CVE-2026-60160LOW3.2
  • VirtualBox logoVirtualBox
  • cpe:2.3:a:oracle:vm_virtualbox
NoNoJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management