New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
A heap-based buffer overflow in 7-Zip’s XZ archive handler, tracked as CVE-2026-14266, could allow code execution when a crafted XZ file is opened, and the issue was fixed in 7-Zip 26.02 on June 25. The flaw carries High severity, affects local file handling, and users should update because products that bundle 7-Zip’s XZ decoder may need separate vendor patches. #7Zip #CVE-2026-14266 #XZ

Keypoints

  • CVE-2026-14266 is a heap-based buffer overflow in 7-Zip’s XZ chunked data processing.
  • Opening a crafted XZ archive can let an attacker execute code in the current process.
  • The flaw is rated 7.0 High by ZDI, with local attack requirements and user interaction needed.
  • 7-Zip 26.02 fixed the issue by correcting length handling in MixCoder_Code in C/XzDec.c.
  • Users should update to 7-Zip 26.02 or later, and vendors shipping 7-Zip must patch their own products.

Read More: https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html