BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

7-Zip XZ flaw enables remote code execution

7-Zip XZ parser flaw CVE-2026-14266 enables remote code execution via crafted archives.

  • A critical heap-based buffer overflow vulnerability, tracked as CVE-2026-14266, was discovered in 7-Zip’s XZ archive handler.
  • An attacker could achieve remote code execution by tricking a user into opening a crafted XZ archive, though the attack requires local user interaction and high complexity.
  • 7-Zip patched the flaw in version 26.02 on June 25, twenty days before the advisory was published by Trend Micro’s Zero Day Initiative.

A critical heap-based buffer overflow vulnerability in 7-Zip’s XZ archive handler could allow an attacker to execute arbitrary code on a victim’s machine, according to a detailed advisory published July 15 by Trend Micro’s Zero Day Initiative (ZDI). The flaw, tracked as CVE-2026-14266, resides in how the archiver processes XZ chunked data and was reported to 7-Zip by researcher Landon Peng on June 5.

- Advertisement -

The exploit occurs when a victim opens a specially crafted XZ file, allowing the attacker to “execute code in the context of the current process,” as described in the advisory. ZDI rates the vulnerability a 7.0 on the CVSS scale, classifying it as High severity with a vector that requires local access and user interaction.

The bug originates in the MixCoder_Code function within the XZ decoder’s source code. The decoder was mistakenly handed the full output-buffer length on each pass instead of the remaining space, leading to an out-of-bounds write condition that version 26.02 patched on June 25 by correctly subtracting bytes already written.

Same flawed length handling has existed in the 7-Zip source code since at least version 21.07 (2021), though it remains unclear which specific releases are actually exploitable. This marks the latest in a series of memory-safety issues for the archiver, following CVE-2026-48095, an NTFS-handler overflow that GitHub Security Lab disclosed with a working proof-of-concept on May 22.

Users must manually install the update from the official site, as the software does not update automatically. The patch shipped twenty days before the public advisory, giving diligent users a head start on mitigation.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

OpenAI launches cheaper GPT-6 Sol and Luna for coding and work tasks

OpenAI launched GPT-6 Sol at $2 per million input tokens and $10 per million...

Kalshi bot stops uniform trades amid wash trade claims

A trading bot repeatedly buying and selling $1 contracts on Kalshi's Zohran Mamdani prediction...

Six Canadian banks explore tokenized CAD deposits

Canada’s six largest banks jointly explore tokenized Canadian dollar deposits to enable digital bank...

Critical AI Gateway Bug Allows Unauthenticated RCE

A critical unauthenticated remote code execution vulnerability (CVE-2026-90898, CVSS 9.8) affects all versions of...

Binance Invests $100M in Circle to Boost USDC Adoption Globally

Binance invested $100 million in Circle, the issuer of the USDC stablecoinBoth companies expanded...

Must Read

10 Best Crypto to Mine Without Special Hardware Equipment

A lot of people mostly think that it takes a difficult process to mine cryptocurrency. today we are going to show you some of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading