Back to IntelRead Original Source
Intel Node
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
mediumvulnerability2026-07-20T09:10:56+00:00source excerpt
vulnerabilitycve
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.