CVE Tools

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

The Hacker NewsBy The Hacker News

PatchXZ decoder in 7-Zip

Our summary

A new vulnerability in 7-Zip, tracked as CVE-2026-14266, allows attackers to execute arbitrary code during the extraction of specially crafted XZ files. The flaw stems from a heap-based buffer overflow in the way 7-Zip handles XZ chunked data. Trend Micro’s Zero Day Initiative disclosed the issue on July 15, and a fix was included in version 26.02, released on June 25. The vulnerability requires user interaction—specifically, opening a malicious file—but does not allow remote exploitation over the network. While no public exploits or proof-of-concepts have been observed yet, users are strongly advised to update to 7-Zip 26.02 or later to mitigate the risk.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store