CVE-2026-48095 is a heap-write overflow vulnerability in 7-Zip's NTFS handler, fixed in version 26.01. It was detailed by GitHub Security Lab with a working proof-of-concept. The flaw could lead to code execution when processing malicious NTFS files.