Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Oracle’s June 2026 Critical Security Patch Update listed 10 new VirtualBox vulnerability fixes, all affecting VirtualBox 7.2.8. Oracle marked all ten attack vectors as local and said none could be remotely exploited without authentication. That does not establish that every flaw was a confirmed “virtual machine escape”: the advisory provides risk-matrix details, not a root-cause account for each vulnerability.

What are the 10 VirtualBox flaws Oracle patched?

Oracle’s June 2026 update, initially released on 16 June, listed ten new VirtualBox CVE entries among its Oracle Virtualization patches. The affected version in every row is VirtualBox 7.2.8. The entries involve Core, Shared Folders, and the VMSVGA device.

CVE Component CVSS 3.1 base score Attack vector
CVE-2026-46974 Core 7.5 Local
CVE-2026-35275 Shared Folders 7.5 Local
CVE-2026-46873 VMSVGA device 7.5 Local
CVE-2026-46768 VMSVGA device 6.0 Local
CVE-2026-46825 VMSVGA device 6.0 Local
CVE-2026-46877 VMSVGA device 6.0 Local
CVE-2026-46874 Core 3.2 Local
CVE-2026-46815 VMSVGA device 3.2 Local
CVE-2026-46816 VMSVGA device 3.2 Local
CVE-2026-46977 VMSVGA device 3.2 Local

Oracle’s matrix scores three entries at 7.5, three at 6.0, and four at 3.2. For the three 7.5 entries, Oracle records high attack complexity. CVE-2026-46974 and CVE-2026-46873 require high privileges; CVE-2026-35275 requires low privileges. These are Oracle’s risk-characterization fields, not proof that a vulnerability is exploitable in any particular installation. See Oracle’s June 2026 advisory for the full matrix, including user-interaction, scope, and confidentiality, integrity, and availability impact fields.

Does “virtual machine escape” describe all ten flaws?

Not on the evidence in Oracle’s June matrix. It identifies affected components, CVSS scores, attack conditions, and impact fields, but does not provide a detailed root-cause narrative establishing that each issue lets code inside a guest virtual machine escape to the host. Oracle also states that none of the ten may be remotely exploitable without authentication. The “local” vector and privileges recorded in the matrix should not be turned into a broader claim about a confirmed guest-to-host escape.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is the June update still the latest VirtualBox advisory?

No. Oracle’s September 2026 Critical Security Patch Update is newer. Its Virtualization matrix lists 19 VirtualBox CVEs affecting version 7.2.16. One of those, CVE-2026-87277, is identified with protocol RDP and marked “Yes” for remote exploitation without authentication. The June figure of ten describes vulnerabilities newly addressed in that June update; it is neither a cumulative total nor the latest count. Oracle’s September 2026 advisory and security-alert index provide the later update details and release dates.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should VirtualBox administrators do?

  1. Check the installed version. Confirm whether the system is running VirtualBox 7.2.8, the version named in all ten June matrix rows.
  2. Check Oracle support eligibility. Oracle says Critical Security Patch Update fixes are provided only for product versions in Premier Support or Extended Support.
  3. Follow Oracle’s supported update route. Oracle recommends staying on actively supported versions and applying security patches without delay. Consult the latest applicable Oracle advisory rather than treating the June update as the final release for VirtualBox.

Oracle’s June advisory says its risk matrices list vulnerabilities newly addressed by the patches associated with that advisory. The patch count therefore refers to that release, not to every unresolved or historically reported VirtualBox issue.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.