logo

New 7-Zip Heap Buffer Overflow Disclosed with Public PoC

ID: c10278e1-cc21-518b-b058-8a1484f7b1da

STIX ID: report--c10278e1-cc21-518b-b058-8a1484f7b1da

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Ddos

...
...

Security researchers disclosed CVE-2026-48095, a heap buffer overflow in 7-Zip 26.00's NTFS handler that can be triggered by a crafted NTFS image to achieve arbitrary code execution; the public release of a Python proof-of-concept (gen_ntfs_sparse.py) raises exploitation risk, so users should update 7-Zip and avoid untrusted archives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.