CVE-2026-13165Patch

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). An attacker who controls the served archive can insert a malicious DLL/SO/DYLIB as a local-file-header entry between the last legitimate entry and the Central Directory, without adding it to the Central Directory. The signature verifier never sees the injected entry and accepts the archive as validly signed; the extractor reads it sequentially and writes the attacker library to the native temp directory with no hash check), while the archive-size check still passes. This can lead to remote code execution. This issue was fixed in version 1.2.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-29: 1Mentions · 2026-06-30: 1PoC Mentioned / Linked · 2026-06-30: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-29: 1Technical Details · 2026-06-30: 106-2906-30
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-06-291
Patch1
2026-06-301
Disclosure1
Full discourse2 posts
  • RIFFSEC@getriffsec
    Patch

    ⚠️ Aktualizujcie mSzafir! CERT Polska opisał podatność CVE-2026-13165 w oprogramowaniu SzafirHost od Krajowej Izby Rozliczeniowej. Problem dotyczy sposobu obsługi archiwum z bibliotekami natywnymi. W uproszczeniu: aplikacja sprawdza podpis jednym parserem, ale rozpakowuje pliki drugim. To może pozwolić atakującemu przemycić złośliwą bibliotekę DLL/SO/DYLIB, która nie zostanie uwzględniona przy weryfikacji, ale zostanie zapisana podczas rozpakowywania. Podatne są wersje SzafirHost wcześniejsze niż 1.2.2. Rekomendacja jest więc prosta: jeżeli używacie SzafirHost, sprawdźcie wersję i zaktualizujcie oprogramowanie. Źródło: CERT Polska

    Post summary

    CERT Polska reports CVE‑2026‑13165, a signature‑verification flaw in SzafirHost versions prior to 1.2.2 that could allow DLL injection. Users are advised to verify and upgrade to the latest version to mitigate the vulnerability.

    000401.4K
    3.0K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-13165 SzafirHost Potential for injection of malicious native libraries into signed archives, turning electronic signature infrastructure into trust and code-execution risk Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-29/TIER_2_CVE-2026-13165.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement

    Post summary

    The post announces a new CVE highlighting a code‑execution vulnerability via malicious native library injection, provides a link to a detailed analysis, but does not mention exploitation, patches, or PoC code directly.

    0000052
    56 followersView on X

Explore more