New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems

A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the tool’s NTFS archive handler. Tracked as CVE-2026-48095 and assigned advisory GHSL-2026-140, the flaw resides in the CInStream::GetCuSize() function inside NtfsHandler.cpp. The function computes the NTFS […]

The post New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: