CVE-2026-14266

Published Jul 29, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-14266 is a heap-based buffer overflow vulnerability found in 7-Zip, a widely used open-source file archiving tool. The flaw specifically arises from the improper handling of XZ chunked data during the decompression process. When 7-Zip processes specially crafted XZ-compressed data, it can trigger a memory corruption where data written to a buffer exceeds its allocated space. This vulnerability allows remote attackers to execute arbitrary code on affected systems. For exploitation, user interaction is required; a target must either open a maliciously crafted archive file or visit a malicious webpage designed to deliver the crafted XZ payload. Successful exploitation results in the execution of malicious code with the privileges of the logged-in user running 7-Zip. The issue has been addressed in 7-Zip version 26.02.

Description
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.
Source
zdi-disclosures@trendmicro.com
NVD status
Analyzed
Products
7-zip

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 3.0

Type
Secondary
Base score
7
Impact score
5.9
Exploitability score
1
Vector string
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

zdi-disclosures@trendmicro.com
CWE-122

Social media

Hype score
Not currently trending
  1. Update 7-Zip Now: CVE-2026-14266 Lets Attackers Run Code on Your PC #Cve #Update7ZipNow #Tech @CallofDuty https://t.co/hGbmbFwP3p

    @HappyGamerNews

    25 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. For defenders, 7-zip cve-2026-14266 turns archive handling into an endpoint pa… should move fast. ZDI disclosed CVE-2026-14266, a 7-Zip XZ decoder heap overflow fixed in 26.02 that can enab… 🔗 Details → https://t.co/AMysRhb3Ya

    @SocXAInvaders

    21 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️7-Zipがリモートコード実行の脆弱性を修正(CVE-2026-14266) 🚨WP2Shell脆弱性、攻撃で悪用されるように:CVE-2026-60137、CVE-2026-63030 〜サイバーセキュリティ週末の話題〜 https://t.co/bnTLCvEBEb

    @MachinaRecord

    21 Jul 2026

    204 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 7-Zipに今年2件目のリモートコード実行脆弱性(CVE-2026-14266)が見つかった。CVSS 7.0。 XZ形式の圧縮データを展開する処理にヒープベースのバッファオーバーフローがあり、細工されたファイルを開くと任意コ

    @joho_no_todai

    19 Jul 2026

    4297 Impressions

    29 Retweets

    68 Likes

    14 Bookmarks

    1 Reply

    0 Quotes

  5. Wordpress祭り中だけど、7-zip、こっちも地味に継続中。悪性書庫を開くだけのRCEは、さすがに放置できない。7-ZipはCVE-2026-14266を26.02で修正。細工したXZ chunked dataでheap-based buffer

    @connect24h

    19 Jul 2026

    1232 Impressions

    3 Retweets

    19 Likes

    9 Bookmarks

    1 Reply

    0 Quotes

Configurations