New 7-Zip security flaw could put hundreds of millions of systems at risk

TL;DR AI
2 min readKey summary
Researchers disclosed a heap-based buffer overflow in 7-Zip, tracked as CVE-2026-48095 and GHSL-2026-140.
The bug can be triggered by opening a specially crafted archive containing an NTFS volume image file.
Impact includes remote code execution or denial of service on affected systems.
7-Zip fixed the issue in version 26.01 after a private report in April, and users are urged to update.
