Dossier
Trend Micro's Zero Day Initiative
Coverage of Trend Micro's Zero Day Initiative in the Nexus archive.
7-Ziporganization1CVE-2026-14266topic1heap-based buffer overflowtopic1XZ archivestopic1code executiontopic1National Institute of Standards and Technologyorganization1Cybersecurity and Infrastructure Security Agencyorganization1National Vulnerability Databaseorganization1CVEstopic1Executive Order 14028topic1Dustin Childsperson1Microsoftorganization1
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
A new vulnerability in 7-Zip (CVE-2026-14266) allows code execution when processing crafted XZ archives due to a heap-based buffer overflow. Trend Micro's Zero Day Initiative disclosed the flaw on July 15, and a fix was released in 7-Zip 26.02 on June 25.
- NIST narrows scope of CVE analysis to keep up with rising tide of vulnerabilities
NIST has narrowed its focus for analyzing CVEs to prioritize those in CISA's catalog, federal government software, and critical software under Executive Order 14028 due to an overwhelming increase in vulnerabilities. The change aims to stabilize the NVD program amid backlogs and funding challenges, shifting away from automatically enriching non-priority CVEs.