PatchSiren cyber security CVE debrief
CVE-2026-60159 Oracle Corporation CVE debrief
A high-severity vulnerability was discovered in Oracle VM VirtualBox, affecting version 7.2.12. This vulnerability, CVE-2026-60159, has a CVSS score of 7.5 and can be exploited by a high-privileged attacker with logon access to the infrastructure where Oracle VM VirtualBox executes. Successful exploitation can lead to a takeover of Oracle VM VirtualBox. The vulnerability is difficult to exploit and requires high privileges. The CVSS vector is CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H, indicating that the vulnerability allows for Confidentiality, Integrity, and Availability impacts.
- Vendor
- Oracle Corporation
- Product
- Oracle VM VirtualBox
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-28
Who should care
System administrators and security teams responsible for managing Oracle VM VirtualBox installations, particularly those with high-privileged access to the infrastructure, should be aware of this vulnerability and take immediate action to mitigate the risk. This includes reviewing and applying patches, restricting access, and monitoring for suspicious activity.
Technical summary
The vulnerability is located in the Core component of Oracle VM VirtualBox and has been rated as HIGH severity with a CVSS score of 7.5. The CVSS vector is CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H, indicating that the vulnerability allows for Confidentiality, Integrity, and Availability impacts. The supported version affected is 7.2.12, and the vulnerability is difficult to exploit, requiring high privileges. The vulnerability's impact can extend beyond Oracle VM VirtualBox to other products.
Defensive priority
Highest priority should be given to applying patches and restricting access due to the high severity and potential impact of the vulnerability. Monitoring and compensating controls should also be implemented to detect and prevent potential exploitation attempts.
Recommended defensive actions
- Apply the latest security patches from Oracle
- Restrict access to the infrastructure where Oracle VM VirtualBox executes
- Monitor for suspicious activity and implement compensating controls
- Perform regular inventory checks to ensure all instances are updated
- Consider implementing additional security measures such as multi-factor authentication
Evidence notes
The CVE record was published on 2026-07-21T22:17:16.547Z and was last modified on 2026-07-28T01:36:49.983Z. The NVD entry is currently Analyzed. The vulnerability has been described in the Oracle security alert for July 2026. This information is based on the available data and may not reflect the full scope or current status of the vulnerability. Further verification is recommended.
Official resources
-
CVE-2026-60159 CVE record
CVE.org
-
CVE-2026-60159 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:16.547Z and has not been modified since then. The NVD entry is currently Analyzed.