🟠 High | Source: The Hacker News
A heap-based buffer overflow in 7-Zip (CVE-2026-14266) allows an attacker to execute arbitrary code on a victim’s machine simply by getting them to open a specially crafted XZ archive. The flaw affects how 7-Zip processes XZ chunked data and was publicly detailed by Trend Micro’s Zero Day Initiative on 15 July 2026. A patched version, 7-Zip 26.02, was released on 25 June 2026.
Security Architect’s Take: Ensure 7-Zip is updated to version 26.02 or later across all endpoints, build pipelines, and cloud-hosted systems — particularly CI/CD runners and file-processing workloads that may handle untrusted archives. Consider blocking or sandboxing extraction of XZ archives at the perimeter until patching is confirmed complete.
Original advisory: New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction