Back to Intel

Intel Node

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

mediumvulnerability2026-07-20T09:10:56+00:00source excerpt
vulnerabilitycve

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.

Read Original Source