← All stories
● Covered by 2 sources · 2 reportsMedium impact

7-Zip Version 26.02 Fixes High-Severity RCE Flaw in XZ Archive Processing

🔄 Updated 74d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 7-Zip 26.02 fixes an RCE vulnerability in XZ archive processing.
  • The flaw allows code execution with user interaction.
  • Discovered by researcher Landon Peng and disclosed by ZDI.
  • Exploitation requires manually opening a malicious archive.
  • 7-Zip lacks an automatic update feature.

Overview

7-Zip has released version 26.02 to fix a remote code execution (RCE) vulnerability. The flaw, CVE-2026-14266, involves XZ-compressed data and could be exploited through specially crafted archives. Discovered by Landon Peng of Lunbun LLC, the issue was publicly addressed by Trend Micro's Zero Day Initiative (ZDI).

Details of the Vulnerability

The flaw exists in the processing of XZ chunked data in 7-Zip, which could trigger a heap-based buffer overflow. This allows an attacker to execute arbitrary code within the context of the current process, contingent upon a user opening a malicious archive. The released fix ensures no overflow occurs by adding buffer space checks during decompression.

User Action Required

Exploitation of this vulnerability requires user interaction, such as opening a corrupted archive delivered through various means. Notably, 7-Zip does not possess an automatic update feature, necessitating users manually download and install version 26.02 to secure their systems.

Importance of Update

Due to 7-Zip's widespread use, this vulnerability could have significant implications if left unpatched. Users need to take proactive steps to update to the secured version, reinforcing the importance of manual vigilance due to the absence of automatic updates.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A high-severity vulnerability in 7-Zip (CVE-2026-14266) can allow local code execution through crafted XZ files. The flaw was patched in version 26.02 on June 25, 2026, but exploitation requires user action to open the malicious file.

7-Zip 26.02 was released to address a remote code execution vulnerability linked to XZ-compressed data. The issue could allow attackers to execute arbitrary code if users open malicious archives, emphasizing the need for timely updates due to the software's popularity.