Skip to content
The Nexus
SECURITYJul 20 · 09:10 UTCTHE HACKER NEWS[email protected] (The Hacker News)

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

A new vulnerability in 7-Zip (CVE-2026-14266) allows code execution when processing crafted XZ archives due to a heap-based buffer overflow. Trend Micro's Zero Day Initiative disclosed the flaw on July 15, and a fix was released in 7-Zip 26.02 on June 25.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting