7-Zip has released version 26.02 to fix a remote code execution (RCE) vulnerability. The flaw, CVE-2026-14266, involves XZ-compressed data and could be exploited through specially crafted archives. Discovered by Landon Peng of Lunbun LLC, the issue was publicly addressed by Trend Micro's Zero Day Initiative (ZDI).
The flaw exists in the processing of XZ chunked data in 7-Zip, which could trigger a heap-based buffer overflow. This allows an attacker to execute arbitrary code within the context of the current process, contingent upon a user opening a malicious archive. The released fix ensures no overflow occurs by adding buffer space checks during decompression.
Exploitation of this vulnerability requires user interaction, such as opening a corrupted archive delivered through various means. Notably, 7-Zip does not possess an automatic update feature, necessitating users manually download and install version 26.02 to secure their systems.
Due to 7-Zip's widespread use, this vulnerability could have significant implications if left unpatched. Users need to take proactive steps to update to the secured version, reinforcing the importance of manual vigilance due to the absence of automatic updates.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A high-severity vulnerability in 7-Zip (CVE-2026-14266) can allow local code execution through crafted XZ files. The flaw was patched in version 26.02 on June 25, 2026, but exploitation requires user action to open the malicious file.
7-Zip 26.02 was released to address a remote code execution vulnerability linked to XZ-compressed data. The issue could allow attackers to execute arbitrary code if users open malicious archives, emphasizing the need for timely updates due to the software's popularity.