CVE Tools
Back to feed
Patch released XZ decoder in 7-Zip rce 7-Zip

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

A new vulnerability in 7-Zip, tracked as CVE-2026-14266, allows attackers to execute arbitrary code during the extraction of specially crafted XZ files. The flaw stems from a heap-based buffer overflow in the way 7-Zip handles XZ chunked data. Trend Micro’s Zero Day Initiative disclosed the issue on July 15, and a fix was included in version 26.02, released on June 25. The vulnerability requires user interaction—specifically, opening a malicious file—but does not allow remote exploitation over the network. While no public exploits or proof-of-concepts have been observed yet, users are strongly advised to update to 7-Zip 26.02 or later to mitigate the risk.