CVE-2026-4111Disclosure

LOWCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-14); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-13: 1Mentions · 2026-03-14: 3Mentions · 2026-03-19: 1Active Exploitation · 2026-03-19: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 2Technical Details · 2026-03-19: 103-1303-1403-19
Signal classification2 categories
Disclosure
480.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-131
Disclosure1
2026-03-143
Disclosure3
2026-03-191
Active Exploitation1
Full discourse5 posts
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    This is where it changes. The researcher pulled the latest libarchive source and found it — CVE-2026-4111, a memory corruption flaw that could let attackers execute code just by convincing someone to extract a crafted archive file.

    Post summary

    The analyst identified CVE-2026-4111 as a memory corruption flaw that can lead to code execution by extracting a crafted archive, but no exploit, PoC, patch, or active exploitation is mentioned.

    1000022
    14 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎤 RadioCSIRT Ep.602 – Jeudi 19 mars 2026 Neuf sujets. Veille cyber quotidienne. 🔴 KEV / CISA – Ajout de CVE-2026-20131 affectant Cisco Secure Firewall et CVE-2026-20963 impactant Microsoft SharePoint. Deux vulnérabilités de type Deserialization of Untrusted Data activement exploitées. 🔴 Endpoint Management – La CISA alerte sur une attaque visant Stryker avec abus de Microsoft Intune. Exploitation de privilèges et détournement de capacités d’administration centralisée. 🔴 Ubiquiti – Vulnérabilité critique dans UniFi Network affectant plusieurs versions. Impact non documenté mais exposition directe des consoles de gestion réseau. 🔴 CERT-FR / Microsoft – Multiples vulnérabilités référencées CVE-2026-23941 à CVE-2026-4111. Impact non spécifié, dépendances Erlang, libexif et libarchive concernées. 🔴 Roundcube – Vulnérabilités multiples incluant SSRF, XSS et CSRF sur Webmail. Atteinte à la confidentialité et exécution de requêtes côté serveur possibles. 🔴 Mitel – Vulnérabilité XSS affectant MiContact Center et MCX. Injection de code côté client permettant manipulation de session et contenu. 🔴 Splunk – Vulnérabilités multiples dans Universal Forwarder. Références CVE-2025-15467, CVE-2026-22795 et CVE-2026-22796. Impact non précisé. 🔴 Python – CVE-2026-3479. Contournement de politique de sécurité dans CPython. Mécanisme d’exploitation non détaillé publiquement. 🔴 VMware Tanzu – Plus de 100 CVE dans les Buildpacks et composants plateforme. Risque Supply Chain étendu sur dépendances logicielles. 🔴 DPRK – IBM X-Force et Flare identifient une opération impliquant 100 000 faux IT workers infiltrant des entreprises occidentales. Usage de VPN, identités frauduleuses et plateformes freelance. 🔴 NCSC – Publication de recommandations sur la sécurisation des visioconférences. Risques liés aux accès, à la gestion des données et aux fonctionnalités IA. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-602-radiocsirt-edition-francaise-veille-cyber-du-jeudi-19-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #CISA #KEV #Cisco #SharePoint #Deserialization #Endpoint #Intune #Ubiquiti #UniFi #CERTFR #Roundcube #SSRF #XSS #CSRF #Mitel #Splunk #Python #VMware #Tanzu #SupplyChain #NorthKorea #DPRK #IBM #Flare #NCSC #ZeroTrust #CVE #CERT #SOC #CISO #CyberDefense #BlueTeam #InfoSec

    Post summary

    The episode announces that CVE‑2026‑20131 and CVE‑2026‑20963 are actively exploited, highlighting real‑world attacks while providing technical details but no PoC or patch information.

    00000101
    413 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4111 A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially c… https://www.cve.org/CVERecord?id=CVE-2026-4111

    Post summary

    CVE-2026-4111 indicates a flaw in libarchive’s RAR5 decompression logic that could be leveraged via specially crafted archives; no PoC, exploit, or patch details are presented in the snippet.

    0000089
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4111 - Red Hat - Red Hat Enterprise Linux 10 - https://www.redpacketsecurity.com/cve-alert-cve-2026-4111-red-hat-red-hat-enterprise-linux-10/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4111 #red-hat #red-hat-enterprise-linux-10

    Post summary

    The tweet announces CVE-2026-4111, affecting Red Hat Enterprise Linux 10, by linking to an external site, but offers no additional technical details or claims beyond the alert.

    00000121
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4111 - Libarchive RAR5 Archive Decompression Infinite Loop Denial of Service Vulnerability Intel Report: https://ift.tt/LFM5lGb

    Post summary

    The alert announces CVE-2026-4111, a libarchive RAR5 denial‑of‑service vulnerability causing an infinite loop during decompression, and provides a link to an Intel report.

    0000036
    340 followersView on X

Explore more