Patch released XZ decoder in 7-Zip rce 7-Zip
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
CVE Tools coverage
A new vulnerability in 7-Zip, tracked as CVE-2026-14266, allows attackers to execute arbitrary code during the extraction of specially crafted XZ files. The flaw stems from a heap-based buffer overflow in the way 7-Zip handles XZ chunked data. Trend Micro’s Zero Day Initiative disclosed the issue on July 15, and a fix was included in version 26.02, released on June 25. The vulnerability requires user interaction—specifically, opening a malicious file—but does not allow remote exploitation over the network. While no public exploits or proof-of-concepts have been observed yet, users are strongly advised to update to 7-Zip 26.02 or later to mitigate the risk.