SzafirHost JAR parser flaw enables RCE
A signature-verification bypass in SzafirHost lets attackers smuggle a malicious native library into a signed archive and achieve remote code execution.
CERT Polska coordinated disclosure of CVE-2026-13165, a vulnerability in SzafirHost caused by a parser discrepancy between the component that verifies archive signatures and the component that extracts native libraries. The verifier reads only the Central Directory of a JAR/ZIP archive, while the extractor reads sequentially from local file headers, allowing an attacker who controls the served archive to insert a malicious DLL, SO, or DYLIB entry that is invisible to the signature check but still extracted and executed with no hash validation.
Because the archive-size check remains valid and the signature verification appears to succeed, the malicious payload is trusted and written to the native temp directory, enabling remote code execution on affected systems. The issue was responsibly reported by researcher Mariusz Maik and has been fixed in SzafirHost version 1.2.2. No evidence of active exploitation was noted in the advisory.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-13165
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free