Critical Vulnerabilities in 7-Zip Enable Code Execution Attacks

Critical Vulnerabilities in 7-Zip Enable Code Execution Attacks

First seen 26 May 2026, 09:04 UTC CybersecuritynewsGbhackersSocprimeHeise.Desecuritylab.github.com+3 87% similarity 72.8

Article Content

Browse articles
ThreatCluster

A critical heap buffer overflow vulnerability has been identified in 7-Zip version 26.00, allowing attackers to execute arbitrary code through a vtable hijack. This flaw, tracked as CVE-2026-48095 and assigned advisory GHSL-2026-140, affects the NTFS archive handler, specifically within the CInStream::GetCuSize() function in NtfsHandler.cpp. Attackers can exploit this vulnerability by crafting malicious archive files that, when opened by victims, can lead to remote code execution and sensitive data leakage. The GitHub Security Lab has disclosed this vulnerability, emphasizing its severity. Users of 7-Zip are advised to update to the latest version to mitigate risks associated with this flaw.

Key Points: • 7-Zip version 26.00 has a critical heap buffer overflow vulnerability (CVE-2026-48095). • Attackers can exploit this flaw via crafted NTFS archive files to execute arbitrary code. • Users are urged to update 7-Zip to the latest version to protect against these vulnerabilities.

ThreatCluster AI

Timeline

2026-05-26
CVE-2026-48095 disclosed
A critical heap buffer overflow in 7-Zip's NTFS handler was disclosed, allowing for remote code execution.
Cybersecuritynews
2026-05-26
Multiple vulnerabilities reported
GitHub Security Lab reported multiple memory safety bugs in 7-Zip 26.00, including CVE-2026-48095.
Gbhackers

Community

Browse all →