CVE-2026-60158: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L).
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-60158
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-601580.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-60158 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Oracle Virtualization (July 23, 2026)cert-fr-avis
- medium[NEW] [medium] Oracle Virtualization: Multiple vulnerabilitiescert-bund
Recent advisories for Oracle VM VirtualBox
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-60162: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). …nvd · 2026-07-21
- mediumCVE-2026-60161: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). …nvd · 2026-07-21
- lowCVE-2026-60160: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). …nvd · 2026-07-21
- highCVE-2026-60159: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). …nvd · 2026-07-21
- highCVE-2026-60155: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). …nvd · 2026-07-21
- highCVE-2026-60150: Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). …nvd · 2026-07-21
More from NVD Recent CVEs
- criticalCVE-2026-8457: The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in a…2026-08-02
- highCVE-2026-18352: The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versi…2026-08-02
- highCVE-2026-13339: The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions…2026-08-02
- unknownCVE-2026-17002: Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2026-08-01
- unknownCVE-2026-18556: Authentication bypass using an alternate path or channel vulnerability in N-able N-central all…2026-08-01