logo

Malformed ZIP Files Allows Attackers to Bypass Antivirus and EDR Detections

ID: 619646df-ceac-59a3-9793-dc3d9c96616c

STIX ID: report--619646df-ceac-59a3-9793-dc3d9c96616c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Abinaya

...
...

The report describes CVE-2026-0866, a critical weakness in archive handling where deliberately malformed ZIP headers (altered compression-method metadata) can cause antivirus and EDR scanners to fail to decompress and scan archives, allowing embedded malicious payloads to evade detection; attackers pair this with custom loaders that ignore the broken metadata to execute the payload. Cisco is confirmed affected, numerous other vendors have unknown status, and the advisory recommends vendors validate archive content against declared metadata, quarantine inconsistent archives, and hunt for custom loaders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.