7-Zip patches XZ-decoder heap overflow | CVE-2026-14266 hits 21.07-26.01, upgrade to 26.02
TL;DR
Trend Micro's ZDI disclosed 7-Zip's CVE-2026-14266 on July 15: a heap-based buffer overflow in XZ chunked data decoding that opens the door to RCE when opening a crafted XZ archive. ZDI scored it 7.0 (High). Affected: 21.07-26.01. Fixed in 26.02 (June 25). No in-the-wild exploitation reported.
Trend Micro's Zero Day Initiative (ZDI) disclosed 7-Zip's CVE-2026-14266 on July 15 — a heap-based buffer overflow in XZ chunked-data decoding. All an attacker needs is to trick a user into opening a crafted XZ archive in 7-Zip to run code on the machine. ZDI rates it 7.0 (High), not the Critical several write-ups reached for — the attack vector is local, requires user interaction, and does not require elevated privileges.
Affected versions span 21.07 through 26.01. The fix landed in 26.02 on June 25. As of July 20, The Hacker News found no public PoC and no credible report of in-the-wild exploitation.
The attack surface is depressingly mundane: an "invoice.xz" attachment on email, a "patch pack.xz" in a Telegram group, a download disguised as a CI artifact. A habitual right-click extract is all it takes for code to run. Every machine that opens archives from outside should be on 26.02 or later — no alternative.
via The Hacker News / BleepingComputer
Affected versions span 21.07 through 26.01. The fix landed in 26.02 on June 25. As of July 20, The Hacker News found no public PoC and no credible report of in-the-wild exploitation.
The attack surface is depressingly mundane: an "invoice.xz" attachment on email, a "patch pack.xz" in a Telegram group, a download disguised as a CI artifact. A habitual right-click extract is all it takes for code to run. Every machine that opens archives from outside should be on 26.02 or later — no alternative.
via The Hacker News / BleepingComputer
