CVE-2026-48095Patch(7-zip / 7-zip)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch 7-zip 7-zip systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)1 << (BlockSizeLog + CompressionUnit), and a crafted image with ClusterSizeLog >= 28 and CompressionUnit == 4 drives the exponent to 32, which is undefined behavior and collapses on x86/x64 so _inBuf is allocated as 1 byte. ReadStream_FALSE then writes up to 256 MB of attacker-controlled data into that 1-byte buffer in 64 KB iterations, and because the CInStream object sits only 304 bytes after _inBuf, its vtable pointer is overwritten and the next dispatched call achieves a vtable hijack. On 32-bit builds the overflow is unconditionally reached; on 64-bit it requires the parallel 8 GB _outBuf allocation to succeed, otherwise failing closed to denial of service. The NTFS handler is enabled by default in stock 7z.dll and, via signature-based fallback matching "NTFS " at offset 3, will open a crafted image regardless of file extension during extraction or testing. Version 26.01 fixes the issue.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 7-zip

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 55 mentions across 17 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 18 signals
  • Patch or workaround mentioned in 23 signals
  • Technical details provided in 41 signals
  • Disclosure: 13 classified signals
  • General: 10 classified signals
  • Peaked 16d ago at 14 mentions (2026-05-26); latest day: 1
  • 55 total mentions across 17 days

Affected systems

Vendors
Products
7-zip

Deep dive

Activity timeline55 mentions / 17d
0471114Mentions · 2026-05-26: 14Mentions · 2026-05-27: 8Mentions · 2026-05-28: 10Mentions · 2026-05-29: 3Mentions · 2026-05-30: 3Mentions · 2026-05-31: 2Mentions · 2026-06-01: 2Mentions · 2026-06-04: 1Mentions · 2026-06-05: 1Mentions · 2026-06-06: 1Mentions · 2026-06-08: 4Mentions · 2026-06-11: 1Mentions · 2026-06-13: 1Mentions · 2026-06-29: 1Mentions · 2026-07-17: 1Mentions · 2026-07-20: 1Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-05-26: 6PoC Mentioned / Linked · 2026-05-27: 5PoC Mentioned / Linked · 2026-05-28: 3PoC Mentioned / Linked · 2026-05-31: 1PoC Mentioned / Linked · 2026-06-13: 1PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-07-29: 1Exploit Tool / Code · 2026-05-26: 1Exploit Tool / Code · 2026-05-27: 2Exploit Tool / Code · 2026-05-28: 2Exploit Tool / Code · 2026-05-31: 1Exploit Tool / Code · 2026-07-29: 1Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-05-30: 1Patch / Workaround · 2026-05-26: 6Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-28: 6Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-06: 1Patch / Workaround · 2026-06-08: 4Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-05-26: 13Technical Details · 2026-05-27: 5Technical Details · 2026-05-28: 6Technical Details · 2026-05-29: 2Technical Details · 2026-05-30: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-01: 2Technical Details · 2026-06-05: 1Technical Details · 2026-06-06: 1Technical Details · 2026-06-08: 4Technical Details · 2026-06-11: 1Technical Details · 2026-06-13: 1Technical Details · 2026-07-17: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-29: 105-2605-2705-2805-2905-3005-3106-0106-0406-0506-0606-0806-1106-1306-2907-1707-2007-29
Signal classification6 categories
Patch
2036.4%
Disclosure
1323.6%
General
1018.2%
PoC
916.4%
Active Exploitation
23.6%
Exploit
11.8%
Referenced assets35 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-2614
Disclosure6General1Patch4PoC3
2026-05-278
Disclosure1General2Patch1PoC4
2026-05-2810
Active Exploitation1Disclosure2General1Patch5PoC1
2026-05-293
Disclosure1General1Patch1
2026-05-303
Active Exploitation1Disclosure1General1
2026-05-312
Exploit1General1
2026-06-012
General1Patch1
2026-06-041
General1
2026-06-051
Disclosure1
2026-06-061
Patch1
2026-06-084
Patch4
2026-06-111
General1
2026-06-131
Disclosure1
2026-06-291
Patch1
2026-07-171
Patch1
2026-07-201
Patch1
2026-07-291
PoC1
Full discourse20 posts
  • Richard Heart@RichardHeartWin
    Patch

    Upgrade your 7zip to 26.01 now, on both windows and linux systems. Or, you could get hacked, if you open an evil file with it. CVE-2026-48095

    Post summary

    The text advises users to upgrade 7zip to version 26.01 to mitigate CVE-2026-48095, acting as a patch advisory.

    5124071.2K7935.3K
    349.7K followersView on X
  • yousukezan@yousukezan
    PoC

    7-Zipに深刻なヒープバッファオーバーフロー脆弱性CVE-2026-48095が見つかった。細工ファイルを開くだけで任意コード実行が可能となり、PoCも既に公開されているため悪用リスクが高まっている。 問題は7-Zip 26.00のNTFSアーカイブ処理に存在する。細工したNTFSイメージにより整数シフト処理が異常値となり、本来256MB必要な領域に1バイトしか確保されなくなる。その後、攻撃者制御データが大量書き込みされ、ヒープ領域とvtableポインタが破壊されることでコード実行へ至る。 危険なのは拡張子偽装でも攻撃可能な点だ。7-Zipは署名ベース検査を行うため、.zipや.rar、.7zを装っていても内部的にNTFSアーカイブとして処理される可能性がある。 GitHub Security LabはPoC生成スクリプト「gen_ntfs_sparse.py」も公開済みで、攻撃コード流用は容易とみられる。利用者には不審アーカイブを開かないことと、即時アップデート適用が推奨されている。 https://securityonline.info/7-zip-heap-buffer-overflow-cve-2026-48095/

    Post summary

    The announcement highlights a newly found heap buffer overflow in 7‑Zip, confirms that a proof‑of‑concept exists on GitHub, provides technical exploitation details and urges immediate updates, but no evidence of active exploitation.

    21621133812738.9K
    14.5K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Nuevas vulnerabilidades de 7-Zip permiten ejecutar código y comprometer sistemas Vulnerabilidad crítica de desbordamiento de búfer en heap en la versión 26.00 de 7-Zip. CVE-2026-48095 (GHSL-2026-140), se encuentra en la función CInStream::GetCuSize() del manejador de archivos NTFS, lo que permitiría a los atacantes lograr la ejecución arbitraria de código mediante el secuestro de una vtable https://blog.elhacker.net/2026/05/nuevas-vulnerabilidades-de-7-zip.html

    Post summary

    The blog post discloses a heap buffer overflow (CVE‑2026‑48095) in 7‑Zip 26.00, describing the affected function and possible arbitrary code execution without providing PoC, exploit, patch, or evidence of current exploitation.

    0401107345.6K
    140.9K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files https://thecybersecguru.com/exploits/cve-2026-48095-7-zip-heap-buffer-overflow/

    Post summary

    The post announces a new 7‑Zip vulnerability (CVE‑2026‑48095) that triggers an NTFS heap overflow through renamed files and provides a link to a PoC exploit.

    017073375.1K
    158.6K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Discover the latest 7-Zip heap buffer overflow vulnerability (CVE-2026-48095). Learn how an NTFS exploit allows code execution and how to stay safe. #Cybersecurity #Vulnerability #7Zip #CVE202648095 #Infosec #Exploit https://securityonline.info/7-zip-heap-buffer-overflow-cve-2026-48095/ https://t.co/xtmumn63f5

    Post summary

    The post announces CVE-2026-48095, describing a heap buffer overflow in 7‑Zip that can be triggered via an NTFS-based exploit to achieve code execution.

    112060184.8K
    12.5K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨 تستخدم كل يوم (7-Zip)؟ حدثه لانه مصابه بثغرات بعضها عمرها قد يصل الى ١٤-١٦ سنه تم اكتشاف ٩ ثغرات في البرنامج اللي يستخدمه مئات الملايين حول العالم من قبل فريق (GitHub Security Lab) 📍 الثغرة الاخطر (CVE-2026-48095): بتقييم (CVSS 8.8)، الخلل عبارة عن (Heap Buffer Overflow) في معالج نظام ملفات (NTFS) داخل البرنامج. هذي الثغرة موجودة من سلسلة (9.x) الخاصة بـ (7-Zip) اللي بدأت تقريباً في عام ٢٠١٠.

    Post summary

    The entry announces the discovery of nine CVE vulnerabilities in 7‑Zip, with technical details provided for CVE-2026‑48095 but no PoC, exploit, or patch information.

    18039235.5K
    50.0K followersView on X
  • 情報の灯台@joho_no_todai
    Patch

    7-Zipにファイルを開くだけで任意のコードを実行される脆弱性(CVE-2026-48095)が見つかりました。 修正版v26.01は4月27日にリリース済みですが、7-Zipには自動更新機能がありません。 Microsoftの正規の認証メールアドレスからフィッシング詐欺メールが届く手口も確認されており、SPF・DKIM・DMARCを全て正当に通過します。 さらにグラーツ工科大学がブラウザのJavaScriptだけでSSDのアクセス遅延を計測し、閲覧中のサイトを推定する手法「FROST」を実証しています。 https://youtu.be/X1YLEnxte_k 3件の対処法と影響範囲を整理しています。 Three satisfying satisfying security flaws.

    Post summary

    CVE-2026-48095 is a file‑open code execution flaw in 7‑Zip; a patch (v26.01) was released on April 27, but no automatic update capability exists and no active exploitation or PoC is reported.

    01702983.7K
    11.1K followersView on X
  • Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]@yarlob
    PoC

    PoC for CVE-2026-48095 in 7-Zip 26.00 on Linux without ASLR bypass. https://t.co/Qmk6paOTsS

    Post summary

    The tweet announces a PoC for CVE-2026-48095 in 7‑Zip 26.00 on Linux, providing a link to the exploit code without mentioning active exploitation, patches, or detailed technical details.

    141231317.6K
    473 followersView on X
  • Frank@jedisct1
    PoC

    CVE-2026-48095 - The 7-Zip NTFS heap overflow that can ruin your day and your network https://thecybersecguru.com/exploits/cve-2026-48095-7-zip-heap-buffer-overflow/

    Post summary

    The blog announces CVE‑2026‑48095, a 7‑Zip NTFS heap overflow, and links to a PoC, but it does not detail active exploitation, patching, or debunking.

    07023102.2K
    17.5K followersView on X
  • Fatal Cybersecurity@fatalcyber
    Patch

    Upgrade your 7zip to 26.01 now, on both windows and linux systems. Or, you could get hacked, if you open an evil file with it. CVE-2026-48095

    Post summary

    The post urges users to update 7zip to version 26.01 to mitigate CVE-2026-48095, with no PoC, exploit, or technical detail disclosed.

    01121312273
    368 followersView on X
  • blackorbird@blackorbird
    General

    The exploitation technique for the 7-Zip vulnerability CVE-2026-48095 feels extremely familiar. I swear I've seen it used in a 7-Zip archive by some APT group before, but I just can't track it down anywhere. https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/

    Post summary

    The post references CVE-2026-48095 and links to a GitHub Security Lab advisory, but offers no actionable PoC, exploitation code, patch, or detailed technical description.

    0502382.8K
    42.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Update now to the 7-Zip CVE-2026-48095 patch. Discover how this critical heap overflow in the NTFS archive handler triggers remote code execution. #7Zip #CVE202648095 #CyberSecurity #RemoteCodeExecution #HeapOverflow #Infosec2026 https://meterpreter.org/7zip-cve-2026-48095-patch-ntfs-heap-overflow/ https://t.co/fpARbEMzDC

    Post summary

    The tweet announces the availability of a patch for the 7‑Zip CVE‑2026‑48095 heap‑overflow vulnerability that enables remote code execution. It urges users to update immediately.

    2711772.0K
    12.5K followersView on X
  • Scooter Software@ScooterSoftware
    Patch

    We've released Beyond Compare 5.2.3.32296. Updated 7-zip to 26.01. Fixes CVE-2026-48095. Fixed support for SFTP server-side CRC32 calculations using the check-file extension. Other minor fixes.

    Post summary

    Beyond Compare and 7‑zip have been updated to patch CVE‑2026‑48095; no exploit, PoC, or active exploitation noted.

    510130971
    2.2K followersView on X
  • Technopat@TechnopatNet
    Disclosure

    ⚠️ 7-Zip’te kritik güvenlik açığı: Milyonlarca sistem risk altında Dünyanın en yaygın kullanılan arşivleme araçlarından 7-Zip’te CVE-2026-48095 kodlu yeni bir güvenlik açığı ortaya çıktı. GitHub Security Lab tarafından duyurulan açık, 7-Zip 26.00 ve önceki sürümleri etkiliyor. Sorun, 7-Zip’in NTFS tabanlı imaj dosyalarını işlerken kullandığı arşiv işleyicisindeki bellek taşması hatasından kaynaklanıyor. Özel hazırlanmış bir arşiv dosyasının açılması, bazı sistemlerde uygulamanın çökmesine; bazı senaryolarda ise sistemde kod çalıştırılmasına yol açabiliyor. Daha da önemlisi, saldırı yüzeyi yalnızca .ntfs veya .img dosyalarıyla sınırlı değil. 7-Zip’in imza tabanlı format algılama yapısı nedeniyle kötü amaçlı NTFS imajları farklı uzantılarla da kullanıcıya gönderilebiliyor. Bu da .zip, .rar veya .7z gibi daha tanıdık arşiv dosyalarının saldırı senaryolarında kullanılabileceği anlamına geliyor. ✅ Etkilenen sürümler: 7-Zip 26.00 ve öncesi ✅ Güvenli sürüm: 7-Zip 26.01 ✅ Öneri: Güncellemeyi geciktirmeyin ✅ Kontrol: Yardım > Hakkında bölümünden sürümünüzü kontrol edin ✅ Sistem yöneticileri: Komut satırı sürümleri ve kütüphaneleri de kontrol etmeli 7-Zip kullanıyorsanız güncellemeyi yalnızca resmi http://7-zip.org adresinden veya güvenilir paket yöneticilerinden yapmanız öneriliyor. Siz sisteminizde hangi 7-Zip sürümünü kullanıyorsunuz?

    Post summary

    A new CVE-2026-48095 in 7‑Zip 26.00 and earlier, caused by a memory‑overflow in the NTFS image handler, can lead to code execution. Updating to 26.01 is recommended; no active exploitation or PoC was reported.

    0111163.5K
    100.1K followersView on X
  • hackyboiz@hackyboiz2
    Disclosure

    [1day-1line] CVE-2026-48095: Heap Buffer Overflow in 7-Zip's NTFS Handler Caused by an Integer Overflow in a Shift Operation Hello, this is gongjae. Today's 1day1line covers a heap buffer overflow vulnerability in the file archiver 7-Zip. When 7-Zip handles an NTFS image, GetCuSize() — the function that computes the compressed-stream buffer size — triggers shift undefined behavior (UB) of the form 1 << 32, causing the input buffer to be under-allocated to just 1 byte. Attacker-controlled data is then written immediately afterward, which is where the bug occurs. For more details, please check out the blog post! https://hackyboiz.github.io/2026/06/13/gongjae/CVE-2026-48095/

    Post summary

    The post announces a heap buffer overflow in 7‑Zip’s NTFS handler caused by an integer‑overflow shift operation, detailing the technical root cause and pointing to a blog for further information.

    000112728
    506 followersView on X
  • ⬣GAINS ⬣@CryptoGainsClub
    General

    @RichardHeartWin @grok any other problems affected by this 7zip evil file cve-2026-48095

    Post summary

    The tweet poses a question about additional issues related to CVE-2026-48095 but provides no further information.

    100412.5K
    1.8K followersView on X
  • CCB Alert@CCBalert
    PoC

    Warning: GitHub Security Lab has disclosed CVE-2026-48095, a critical heap buffer overflow in the 7Zip NTFS handler that could allow remote attackers to execute arbitrary code when a victim opens a crafted archive file. Public PoC is available. #Patch #Patch #Patch

    Post summary

    GitHub Security Lab disclosed CVE-2026-48095—a critical heap buffer overflow in the 7Zip NTFS handler—along with a publicly available Proof of Concept, but no active exploitation or patch information has yet been reported.

    04020746
    7.2K followersView on X
  • nabe|現場エンジニアが趣味でAI活用@nabe_hobby_ai
    Patch

    ⚠️ 7-Zipの脆弱性(CVSS 8.8)、開くだけでコード実行。拡張子偽装も通る。数億台規模のリスクで、26.01へのアップデートが急務。 「7-Zip CVE-2026-48095 開くだけで任意コード実行」 https://www.tomshardware.com/tech-industry/cyber-security/wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk #AI #AI活用 #個人開発 #エンジニア #生成AI

    Post summary

    The post highlights a severe CVE-2026-48095 in 7‑Zip that allows code execution, stresses the urgent need to update to version 26.01, but provides no proof of exploitation or exploit code.

    00030312
    26 followersView on X
  • IT-ADMlNISTRATOR@ita_blog
    Patch

    🚨 Kritische Sicherheitslücke in 7-Zip Im weit verbreiteten Packprogramm 7-Zip wurde eine schwere Schwachstelle entdeckt (CVE-2026-48095, CVSS 8,8). Ein Heap Buffer Overflow im NTFS-Archivhandler ermöglicht es Angreifern, mit einer einzigen präparierten Datei beliebigen Code auf dem Zielsystem auszuführen – auf Rechnern mit mindestens 16 GByte RAM ist das laut Forschern realistisch. Besonders brisant: Die Lücke lässt sich mit Dateien jeder Dateiendung ausnutzen, da 7-Zip Archive anhand ihres Inhalts erkennt. Die gute Nachricht – der Patch ist bereits da: Version 26.01 schließt die Lücke. Jetzt ist der richtige Zeitpunkt, den Rollout zu starten und besonders Systeme im Blick zu behalten, auf denen regelmäßig externe Dateien entpackt werden. 👉https://www.it-administrator.de/7zip-schwachstelle-codeausfuehrung-dateiendung #7Zip #CVE #Patchmanagement #ITSecurity #SysAdmin #Vulnerability

    Post summary

    A severe heap buffer overflow vulnerability (CVE-2026-48095) in 7‑Zip permits arbitrary code execution via crafted files; the flaw is fixed in version 26.01, which should be deployed promptly.

    02010162
    2.8K followersView on X
  • キタきつね@foxbook
    PoC

    7-Zipの新たなヒープバッファオーバーフローの脆弱性が、公開された概念実証(PoC)とともに明らかにされました 7-Zipの新たなヒープバッファオーバーフローの脆弱性が、公開された概念実証(PoC)とともに明らかにされました #DailyCyberSecurity (May 26) https://securityonline.info/7-zip-heap-buffer-overflow-cve-2026-48095/

    Post summary

    A heap buffer overflow vulnerability in 7‑Zip (CVE‑2026‑48095) has been disclosed, with a published proof‑of‑concept available, but no patch or active exploitation details are provided.

    00021346
    4.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App7-zip7-zip---

Explore more