As cited
Copy frozen at (site build).
vulnerabilities
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
A heap-based buffer overflow in 7-Zip's XZ archive processing (CVE-2026-14266) allows remote code execution when opening malicious files. The vulnerability was disclosed by Trend Micro's Zero Day Initiative on July 15, with a patch available since June 25 in version 26.02.
Why it matters: Organizations and users who extract XZ archives face immediate code execution risk if they have not upgraded to 7-Zip 26.02; prompt patching is required.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
A heap-based buffer overflow in 7-Zip's XZ archive processing (CVE-2026-14266) allows remote code execution when opening malicious files. The vulnerability was disclosed by Trend Micro's Zero Day Initiative on July 15, with a patch available since June 25 in version 26.02.
Why it matters: Organizations and users who extract XZ archives face immediate code execution risk if they have not upgraded to 7-Zip 26.02; prompt patching is required.
- Source published
- First seen by Cybersecurity Tracker