CVE-2026-21955 is an easily exploitable vulnerability in the Core component of Oracle VM VirtualBox affecting supported versions 7.1.14 and 7.2.4. The issue requires a high-privileged attacker with logon access to the infrastructure on which VirtualBox executes. Oracle indicates that successful exploitation can compromise and take over Oracle VM VirtualBox, and that the vulnerability has scope change, meaning exploitation may significantly affect additional products or components beyond the vulnerable VirtualBox instance. The published CVSS v3.1 vector is AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, indicating local attack vector, low attack complexity, no user interaction, and high impact to confidentiality, integrity, and availability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone C exploit for CVE-2026-21955 targeting the VMware SVGA virtual graphics device/backend rather than a remote network service. The repo contains one main exploit source file (exp.c) plus helper/device-definition files (svga.c, svga.h, svga_reg.h, svga_types.h) and a minimal README. Structure and purpose: - exp.c: core exploit logic. It initializes the SVGA FIFO, programs VMware SVGA commands directly, shapes backend heap state with many MOB/context/view objects, leaks host pointers, parses leaked structures to locate reusable anchors and backend function tables, establishes a dangling-reference-based arbitrary read/write primitive using forged guest-backed objects, derives sensitive host addresses including a WinExec target, and finally triggers code execution. - svga.c / svga.h: userspace access layer for the VMware SVGA PCI device. It locates the VMware SVGA2 PCI function, enables I/O privileges, maps BARs, reads/writes SVGA registers, and writes FIFO commands. - svga_reg.h / svga_types.h: imported VMware header material defining registers, FIFO layout, and types. Exploit capabilities: 1. Direct hardware interaction with the VMware SVGA virtual device from a privileged guest process. 2. Heap grooming/reclamation using guest-backed MOBs and DX contexts/views. 3. Information disclosure: stage 1 leaks host/backend pointers from corrupted/reclaimed structures. 4. Primitive building: stage 2 establishes a dangling object and forges GBO/MOB-related metadata to gain arbitrary read/write-like effects against backend memory. 5. Address derivation: stage 3 computes important backend pointers such as pThisCC, pFuncsDX/pfnentry, and a WinExec address. 6. Code execution: final stage causes DX_DEFINE_CONTEXT processing to invoke WinExec with the string "calc", demonstrating host/backend RCE. The exploit is operational rather than a mere PoC because it contains a complete end-to-end chain and a concrete payload, but the payload is hardcoded and not generalized into a reusable framework. No network, web, or C2 endpoints are present; the only fingerprintable targets are the VMware PCI device identifiers, SVGA registers/ports, and the specific FIFO command IDs used to manipulate the virtual graphics backend.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.