URL has been copied successfully!
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.The overflow lets an attacker “execute code in the context of the current process,” per the

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link