Security · 17h ago
7-Zip Flaw Allows Code Execution via Malicious XZ Archives
A heap-based buffer overflow in 7-Zip (CVE-2026-14266) lets attackers execute code by opening a crafted XZ archive. Trend Micro's ZDI disclosed the flaw on July 15, after a fix shipped in version 26.02 on June 25. The vulnerability affects how the tool processes XZ chunked data, enabling remote code execution in the current process.
Meridian48 take
While patched, the flaw underscores how even trusted compression tools can become attack vectors, especially given 7-Zip's widespread use.
Read the full reporting
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction →
The Hacker News
7-zipvulnerability