BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

7-Zip XZ flaw enables remote code execution

7-Zip XZ parser flaw CVE-2026-14266 enables remote code execution via crafted archives.

  • A critical heap-based buffer overflow vulnerability, tracked as CVE-2026-14266, was discovered in 7-Zip’s XZ archive handler.
  • An attacker could achieve remote code execution by tricking a user into opening a crafted XZ archive, though the attack requires local user interaction and high complexity.
  • 7-Zip patched the flaw in version 26.02 on June 25, twenty days before the advisory was published by Trend Micro’s Zero Day Initiative.

A critical heap-based buffer overflow vulnerability in 7-Zip’s XZ archive handler could allow an attacker to execute arbitrary code on a victim’s machine, according to a detailed advisory published July 15 by Trend Micro’s Zero Day Initiative (ZDI). The flaw, tracked as CVE-2026-14266, resides in how the archiver processes XZ chunked data and was reported to 7-Zip by researcher Landon Peng on June 5.

- Advertisement -

The exploit occurs when a victim opens a specially crafted XZ file, allowing the attacker to “execute code in the context of the current process,” as described in the advisory. ZDI rates the vulnerability a 7.0 on the CVSS scale, classifying it as High severity with a vector that requires local access and user interaction.

The bug originates in the MixCoder_Code function within the XZ decoder’s source code. The decoder was mistakenly handed the full output-buffer length on each pass instead of the remaining space, leading to an out-of-bounds write condition that version 26.02 patched on June 25 by correctly subtracting bytes already written.

Same flawed length handling has existed in the 7-Zip source code since at least version 21.07 (2021), though it remains unclear which specific releases are actually exploitable. This marks the latest in a series of memory-safety issues for the archiver, following CVE-2026-48095, an NTFS-handler overflow that GitHub Security Lab disclosed with a working proof-of-concept on May 22.

Users must manually install the update from the official site, as the software does not update automatically. The patch shipped twenty days before the public advisory, giving diligent users a head start on mitigation.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Senate CLARITY Act adds Dem customer protections

The US Senate is nearing a vote on the Digital Asset Market Clarity (CLARITY)...

FakeGit campaign uses 800 fake AI tools to spread SmartLoader malware

Cybersecurity researchers uncovered nearly 7,600 malicious GitHub repositories in the FakeGit campaign, with over...

Google’s New Frozen v2 Chip Aims for 2028 Launch

Google is developing a new server chip called Frozen v2, designed to optimize its...

Russia Duma approves crypto for international trade

Russia's State Duma will hold final votes on a comprehensive crypto bill on July...

Saylor breaks 2.5x mNAV promise, stock plummets 75%

Strategy sold $14.3 billion of MSTR stock below the 2.5x mNAV threshold it pledged...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading