PatchSiren cyber security CVE debrief
CVE-2026-60158 Oracle Corporation CVE debrief
A vulnerability was discovered in Oracle VM VirtualBox, specifically in the Core component. The affected version is 7.2.12. This difficult-to-exploit vulnerability requires a low-privileged attacker with logon access to the infrastructure where Oracle VM VirtualBox executes. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data or all Oracle VM VirtualBox accessible data, as well as a partial denial of service (partial DOS) of Oracle VM VirtualBox.
- Vendor
- Oracle Corporation
- Product
- Oracle VM VirtualBox
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-28
Who should care
System administrators and security teams responsible for managing Oracle VM VirtualBox installations should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The vulnerability in Oracle VM VirtualBox has a CVSS 3.1 Base Score of 6.4, indicating a medium severity level. The CVSS Vector is (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L). The vulnerability allows a low-privileged attacker with logon access to compromise Oracle VM VirtualBox, potentially impacting additional products. Successful attacks can result in unauthorized data modifications and partial DOS.
Defensive priority
Medium priority should be given to patching or mitigating this vulnerability, as it requires low privileges to exploit and can have significant impacts on data integrity and availability.
Recommended defensive actions
- Apply the latest security patches for Oracle VM VirtualBox version 7.2.12.
- Implement compensating controls to monitor and restrict access to critical data and systems.
- Conduct regular inventory checks to ensure all VirtualBox instances are up-to-date and compliant.
- Enhance monitoring and exception tracking to detect potential exploitation attempts.
- Consider implementing additional security measures such as multi-factor authentication and least privilege access.
Evidence notes
The CVE record was published on 2026-07-21T22:17:16.433Z and last modified on 2026-07-28T01:36:13.947Z. The NVD entry is currently Analyzed. The vulnerability details are based on the official CVE and NVD records.
Official resources
-
CVE-2026-60158 CVE record
CVE.org
-
CVE-2026-60158 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:16.433Z and has not been modified since then. The NVD entry is currently Analyzed.