Critical 7-Zip XZ Buffer Overflow CVE-2026-14266 Patched in Version 26.02
A critical heap-based buffer overflow vulnerability, tracked as CVE-2026-14266, was disclosed on July 20, 2026, affecting 7-Zip versions 21.07 through 26.01 across Windows, macOS, and Linux. The flaw resides in the XZ archive decoder's MixCoder_Code function, where a miscalculation of remaining buffer space can allow an attacker to execute arbitrary code by tricking a user into opening a malicious XZ file. Researcher Landon Peng of Lunbun LLC discovered and reported the issue to the project on June 5, 2026, with the Zero Day Initiative assigning it a CVSS v3.0 score of 7.0 (High). No public proof-of-concept or active exploitation had been observed as of the publication date, though the attack surface is compatible with phishing and malicious attachment campaigns. Users and organizations are advised to upgrade immediately to 7-Zip 26.02, released June 25, 2026, which resolves the vulnerability.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in