Vulnerabilities · 56 days ago
Updating 7-Zip closes the bug in the standalone archiver, but it does not automatically repair products that bundled the same XZ decoder. The issue is a heap overflow in how 7-Zip counts free space while unpacking a crafted XZ archive, so the unsafe write happens inside the process that opens the file.
7-Zip 26.02 fixes CVE-2026-14266. The catch is that downstream software embedding the decoder may still carry the same flaw until its own vendor ships a separate patch, so patch status has to be checked in both the user-installed app and any bundled components.
3 sources covering this story
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
CVE-2026-14266 is a high-severity heap overflow in 7-Zip’s XZ decoder that could run code when a user opens a crafted archive.
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
Zero Day Initiative Advisories
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability July 15th, 2026 Vulnerability Details This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.
Part of the PlainSec briefing for 2026-07-19