Security · 14h ago
Critical 7-Zip XZ Buffer Overflow Patched in Version 26.02
A heap-based buffer overflow in 7-Zip's XZ decoder (CVE-2026-14266) allows remote code execution via crafted archives. Versions 21.07 through 26.01 are affected, with a CVSS score of 7.0. Users should upgrade to 7-Zip 26.02 immediately.
Meridian48 take
While no active exploitation has been reported, the local attack vector and 7-Zip's ubiquity make this a high-priority patch for both consumers and enterprises.
Read the full reporting
Critical 7‑Zip XZ Buffer Overflow (CVE‑2026‑14266) Discovered and Patched →
DEV Community
7-zipbuffer-overflow