Vulnerabilities & Exploits
7-Zip Fix Leaves Embedded Decoders Behind Updating 7-Zip closes the bug in the standalone archiver, but it does not automatically repair products that bundled the same XZ decoder. The issue is a heap overflow in how 7-Zip counts free space while unpacking a crafted XZ archive, so the unsafe write happens inside the process that opens the file.
7-Zip 26.02 fixes CVE-2026-14266 . The catch is that downstream software embedding the decoder may still carry the same flaw until its own vendor ships a separate patch, so patch status has to be checked in both the user-installed app and any bundled components.
3 sources · Jul 20
CVE-2026-14266 NVD KEV
Timeline Sources Jul 20 The Hacker News
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
CVE-2026-14266 is a high-severity heap overflow in 7-Zip’s XZ decoder that could run code when a user opens a crafted archive.
original Jul 18 BleepingComputer
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
original Jul 15 Zero Day Initiative Advisories
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability July 15th, 2026 Vulnerability Details This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.
original Part of the PlainSec briefing for 2026-07-18
Every edition of this story: 7-Zip Fix Leaves Embedded Decoders Behind
More from today
Vulnerabilities & Exploits
7-Zip Fix Leaves Embedded Decoders Behind Updating 7-Zip closes the bug in the standalone archiver, but it does not automatically repair products that bundled the same XZ decoder. The issue is a heap overflow in how 7-Zip counts free space while unpacking a crafted XZ archive, so the unsafe write happens inside the process that opens the file.
7-Zip 26.02 fixes CVE-2026-14266 . The catch is that downstream software embedding the decoder may still carry the same flaw until its own vendor ships a separate patch, so patch status has to be checked in both the user-installed app and any bundled components.
3 sources · Jul 20
CVE-2026-14266 NVD KEV
Timeline Sources Jul 20 The Hacker News
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
CVE-2026-14266 is a high-severity heap overflow in 7-Zip’s XZ decoder that could run code when a user opens a crafted archive.
original Jul 18 BleepingComputer
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
original Jul 15 Zero Day Initiative Advisories
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability July 15th, 2026 Vulnerability Details This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.
original Part of the PlainSec briefing for 2026-07-18
Every edition of this story: 7-Zip Fix Leaves Embedded Decoders Behind
More from today