Crypto Ticker:
sysadmin from 4sysops.com

7-Zip 26.02 patches RCE flaw triggered by malicious XZ archives

IT News
Jul 19, 2026 at 19:38
53 Views
0 Comments
7-Zip 26.02 patches RCE flaw triggered by malicious XZ archives

7-Zip version 26.02 addresses a remote code execution vulnerability tracked as CVE-2026-14266 that stems from a heap-based buffer overflow when processing specially crafted XZ-compressed data. An attacker can trigger the flaw if a user opens a malicious archive or visits a page delivering a crafted XZ payload, allowing arbitrary code to run with the privileges of the logged-in user. The issue was disclosed by researcher Landon Peng and detailed in a Zero Day Initiative advisory, with the patch adding checks to prevent the decoder from writing beyond available buffer space. Source

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!