securityonline.info 5/26/2026, 2:32:24 AM · external

7 Zip flaw CVE-2026-48095 lets attackers run code via NTFS images

7 Zip flaw CVE-2026-48095 lets attackers run code via NTFS images
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical security flaw in the file archiver 7-Zip, tracked as CVE-2026-48095, has been discovered, allowing attackers to execute arbitrary code or crash applications. Found by Jaroslav Lobačevski from GitHub Security Lab, the flaw arises from a heap buffer overflow caused by an under-allocation error in the NTFS compressed stream buffer during size computation. Attackers can exploit this vulnerability through crafted NTFS images, affecting various archive file types.

With public disclosure of the flaw and accessible proof-of-concept code, users are advised to exercise caution and promptly update their 7-Zip installations to prevent potential exploits.

View Primary Source Via securityonline.info

Article by CyberSIXT