VORANT. Threat Intelligence Sign in Get the full feed

SzafirHost JAR parser flaw enables RCE

medium vulnerability

A signature-verification bypass in SzafirHost lets attackers smuggle a malicious native library into a signed archive and achieve remote code execution.

CERT Polska coordinated disclosure of CVE-2026-13165, a vulnerability in SzafirHost caused by a parser discrepancy between the component that verifies archive signatures and the component that extracts native libraries. The verifier reads only the Central Directory of a JAR/ZIP archive, while the extractor reads sequentially from local file headers, allowing an attacker who controls the served archive to insert a malicious DLL, SO, or DYLIB entry that is invisible to the signature check but still extracted and executed with no hash validation.

Because the archive-size check remains valid and the signature verification appears to succeed, the malicious payload is trusted and written to the native temp directory, enabling remote code execution on affected systems. The issue was responsibly reported by researcher Mariusz Maik and has been fixed in SzafirHost version 1.2.2. No evidence of active exploitation was noted in the advisory.

Mentioned in this report

Vulnerabilities CVE-2026-13165

Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-13165

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free