BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

7-Zip XZ flaw enables remote code execution

7-Zip XZ parser flaw CVE-2026-14266 enables remote code execution via crafted archives.

  • A critical heap-based buffer overflow vulnerability, tracked as CVE-2026-14266, was discovered in 7-Zip’s XZ archive handler.
  • An attacker could achieve remote code execution by tricking a user into opening a crafted XZ archive, though the attack requires local user interaction and high complexity.
  • 7-Zip patched the flaw in version 26.02 on June 25, twenty days before the advisory was published by Trend Micro’s Zero Day Initiative.

A critical heap-based buffer overflow vulnerability in 7-Zip’s XZ archive handler could allow an attacker to execute arbitrary code on a victim’s machine, according to a detailed advisory published July 15 by Trend Micro’s Zero Day Initiative (ZDI). The flaw, tracked as CVE-2026-14266, resides in how the archiver processes XZ chunked data and was reported to 7-Zip by researcher Landon Peng on June 5.

- Advertisement -

The exploit occurs when a victim opens a specially crafted XZ file, allowing the attacker to “execute code in the context of the current process,” as described in the advisory. ZDI rates the vulnerability a 7.0 on the CVSS scale, classifying it as High severity with a vector that requires local access and user interaction.

The bug originates in the MixCoder_Code function within the XZ decoder’s source code. The decoder was mistakenly handed the full output-buffer length on each pass instead of the remaining space, leading to an out-of-bounds write condition that version 26.02 patched on June 25 by correctly subtracting bytes already written.

Same flawed length handling has existed in the 7-Zip source code since at least version 21.07 (2021), though it remains unclear which specific releases are actually exploitable. This marks the latest in a series of memory-safety issues for the archiver, following CVE-2026-48095, an NTFS-handler overflow that GitHub Security Lab disclosed with a working proof-of-concept on May 22.

Users must manually install the update from the official site, as the software does not update automatically. The patch shipped twenty days before the public advisory, giving diligent users a head start on mitigation.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

StreamRat Android Trojan Hits 570K Meta Users via Fake Ads

Cybersecurity firm ThreatFabric uncovered a new Android banking trojan called StreamRat, spread via fake...

Trump $1 coin enters circulation, on sale today

The U.S. Mint has released a commemorative 2026 $1 coin featuring President Donald Trump,...

Norway plans smart glasses crackdown, facial recognition ban

Norway plans to regulate smart glasses more strictly and may ban facial recognition in...

Morgan Stanley Warns Limited Cybercabs May Hurt Tesla Shares

Morgan Stanley reiterated an 'Equal Weight' rating and $400 price target on Tesla, implying...

NYDFS tells X Money to halt interest payments to New Yorkers

NYDFS told X Money it cannot pay bank-like interest on non-bank deposits for New...

Must Read

9 Best Books On Ethereum And Blockchain Technology

QUICK LINKSHow to Choose Your First Blockchain Book: A Simple Framework1. Define Your Goal: Are you looking to Build, Invest, or Understand?2. Assess Your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading