← Back to CVE intelligence
CVE intelligence

CVE-2026-15028

Vulnerability intelligence

Published Jul 10, 2026Sources checked Sep 12, 2026
3.9LOWCVSS out of 10
What this means

Review the available evidence

CVE-2026-15028 and is rated Low severity with a CVSS score of 3.9. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

CISA KEVNot listedBased on the latest collected catalog
EPSS0.2%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-15028?

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.