[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMvr0pCLXOMgOeNyesD6ub3j0645ilLN6ncvCSnyc3EY":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"30cd2a7d-fcde-4839-92cb-e1dc4b5b3cb7","New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction","new-7-zip-vulnerability-could-let-crafted-xz-archives-run-code-during-extraction-b8d589","Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker \"execute code in the context of the current process,\" per the","CVE-2026-14266 is a heap-based buffer overflow in 7-Zip's XZ archive handler that could allow remote code execution when opening a crafted XZ file. The vulnerability was patched on June 25 in version 26.02, with details disclosed by Trend Micro's Zero Day Initiative on July 15. The flaw has a CVSS score of 7.0 (High) and requires local delivery and user interaction; no public PoC or wild exploitation has been reported as of July 20, 2026.","Heap buffer overflow in 7-Zip XZ decoder allows code execution; patched in v26.02.","New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction Swati KhandelwalJul 20, 2026Vulnerability \u002F Endpoint Security Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker \"execute code in the context of the current process,\" per the advisory. The code runs with the token 7-Zip itself holds and gains no privileges of its own. On Windows, a normally launched 7-Zip runs under a filtered standard-user token even on an administrator account, so the attacker inherits those limited rights unless the program was started elevated. The bug came in from Landon Peng of Lunbun LLC, who reported it to 7-Zip on June 5. ZDI rates the flaw 7.0, or High, not the Critical several write-ups reached for. The full CVSS 3.0 vector is AV:L\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H. The AV:L makes it a local attack vector, not a network-reachable or no-click one. ZDI's \"remote code execution\" describes a remote attacker delivering the file, which the victim still has to open, whether it arrives by email, a download, or a web page that hands it to 7-Zip. The high attack complexity makes reliable exploitation harder still. As of July 20, 2026, The Hacker News found no public proof-of-concept for the bug and no credible report of exploitation in the wild. The Hacker News compared the XZ decoder source across releases. The fix lands in one function, MixCoder_Code in C\u002FXzDec.c. When an XZ stream runs its output through a filter, the decoder was handed the full output-buffer length on each pass instead of the space left after earlier writes. That gave it more room to work with than the buffer held, the out-of-bounds write condition ZDI describes. Version 26.02 subtracts the bytes already written and bails out if that running total ever exceeds the buffer. The same flawed length handling appears unchanged in 7-Zip source back to at least version 21.07 (2021), though neither ZDI nor 7-Zip has said which releases are actually exploitable. CVE-2026-14266 is the latest in a run of memory-safety bugs in 7-Zip's archive handlers. On April 27, version 26.01 fixed a batch of them, including the higher-scored CVE-2026-48095, an NTFS-handler heap-write overflow that GitHub Security Lab detailed on May 22 with a working proof-of-concept. The XZ flaw is the quieter of the two so far, and 26.02 rolls up every one of these fixes, so one update covers them all. So update to 7-Zip 26.02 or later on every machine that opens archives from outside. Updating is a manual install from the official site, so set-and-forget machines will not pick it up on their own. Any product that ships a vulnerable copy of 7-Zip's XZ decoder needs its own vendor fix. The patch went out 20 days before the advisory, so anyone who updated in late June was covered before the details were public. For once, updating gets you ahead of the problem instead of chasing it. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Application Security, Code Execution, endpoint security, Patch Management, Software Security, Vulnerability, Windows ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fnew-7-zip-vulnerability-could-let.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhuAoanL7LxDYHynfggiOQo_RDymqYrFlfnRNrstIG6KgYuDWk2uR0eZDx_vCSLWsjTmP5LohkMSGQ_sc32hE4TGqqUCkGwsDlOUzP3bb-Ib-whRLliIb0YVozTMZF-lgSsPJr55l7GPjR1Xq-sH7dieWTBNnZsttdSfOxowTrEZImrcJ-_cI6i4zVFlII\u002Fs1600\u002F7-zip.jpg","2026-07-20T09:10:56+00:00","2026-07-20T10:00:16.48969+00:00",8,[18,21,24,27],{"name":19,"type":20},"7-Zip","product",{"name":22,"type":23},"Trend Micro","vendor",{"name":25,"type":26},"XZ archive format","technology",{"name":28,"type":23},"GitHub Security Lab","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":29,"icon":31,"name":32,"slug":33},null,"Vulnerabilities","vulnerabilities",[35],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",[41,45],{"type":42,"value":43,"context":44},"cve","CVE-2026-14266","Heap-based buffer overflow in 7-Zip XZ decoder allowing RCE via crafted archives",{"type":42,"value":46,"context":47},"CVE-2026-48095","NTFS-handler heap-write overflow in 7-Zip fixed in v26.01"]