New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems
ID: bec12cca-e96b-534c-85f6-9fdeb23e0873
STIX ID: report--bec12cca-e96b-534c-85f6-9fdeb23e0873
Feed Name: cybersecurityNews.com
A critical heap buffer overflow (CVE-2026-48095) in 7-Zip up through 26.00 allows arbitrary code execution when a crafted NTFS image triggers a 32-bit shift undefined behavior in CInStream::GetCuSize, producing a one-byte allocation that is then overwritten leading to a vtable hijack. Both 32- and 64-bit builds are affected, the flaw is extension-agnostic (any file extension matching the NTFS signature can trigger it), and the advisory rates it CVSS 3.1 8.8 — users should update immediately and avoid opening untrusted archives or disk images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
