Home/News/7-Zip Vulnerability Allows Code Execution Via Crafted XZ Archives
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

7-Zip Vulnerability Allows Code Execution Via Crafted XZ Archives

7-Zip Vulnerability Allows Code Execution Via Crafted XZ Archives

A critical vulnerability, identified as CVE-2026-14266, has been discovered in the 7-Zip file archiver that could allow attackers to execute arbitrary code on a user's machine. The flaw resides in the software's handling of XZ chunked data, specifically a heap-based buffer overflow. This vulnerability can be triggered when a user opens a malicious XZ archive that has been carefully crafted by an attacker. The potential for code execution means that an attacker could gain control over the user's system in the context of the running 7-Zip process.

Trend Micro's Zero Day Initiative (ZDI) disclosed the details of this vulnerability on July 15. The ZDI is known for its work in identifying and reporting security flaws to vendors, often providing a window for patches before public disclosure. The nature of the exploit involves the processing of XZ chunked data, a feature within the XZ compression format that 7-Zip supports. A successful exploitation would allow an attacker to execute code within the same privileges as the 7-Zip application itself, which could lead to further system compromise.

Fortunately, a fix for this vulnerability has already been implemented and released. 7-Zip version 26.02, which includes the patch for CVE-2026-14266, was shipped on June 25. Users of 7-Zip are strongly advised to update to the latest version to protect themselves from this potential threat. The vulnerability's classification as a heap-based buffer overflow indicates a common type of memory corruption bug that attackers frequently leverage to achieve code execution. The ability to execute code in the context of the current process is a significant security risk, underscoring the importance of timely software updates.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next