CVE-2026-14266

7-Zip

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-14266 is a heap-based buffer overflow vulnerability found in 7-Zip, a widely used open-source file archiving tool. The flaw specifically arises from the improper handling of XZ chunked data during the decompression process. When 7-Zip processes specially crafted XZ-compressed data, it can trigger a memory corruption where data written to a buffer exceeds its allocated space. This vulnerability allows remote attackers to execute arbitrary code on affected systems. For exploitation, user interaction is required; a target must either open a maliciously crafted archive file or visit a malicious webpage designed to deliver the crafted XZ payload. Successful exploitation results in the execution of malicious code with the privileges of the logged-in user running 7-Zip. The issue has been addressed in 7-Zip version 26.02.

Description
-

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

References

Sources include official advisories and independent security research.