CVE-2026-14266
AI description
CVE-2026-14266 is a heap-based buffer overflow vulnerability found in 7-Zip, a widely used open-source file archiving tool. The flaw specifically arises from the improper handling of XZ chunked data during the decompression process. When 7-Zip processes specially crafted XZ-compressed data, it can trigger a memory corruption where data written to a buffer exceeds its allocated space. This vulnerability allows remote attackers to execute arbitrary code on affected systems. For exploitation, user interaction is required; a target must either open a maliciously crafted archive file or visit a malicious webpage designed to deliver the crafted XZ payload. Successful exploitation results in the execution of malicious code with the privileges of the logged-in user running 7-Zip. The issue has been addressed in 7-Zip version 26.02.
- Description
- -
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
1
⚠️7-Zipがリモートコード実行の脆弱性を修正(CVE-2026-14266) 🚨WP2Shell脆弱性、攻撃で悪用されるように:CVE-2026-60137、CVE-2026-63030 〜サイバーセキュリティ週末の話題〜 https://t.co/bnTLCvEBEb
@MachinaRecord
21 Jul 2026
91 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
7-Zipに今年2件目のリモートコード実行脆弱性(CVE-2026-14266)が見つかった。CVSS 7.0。 XZ形式の圧縮データを展開する処理にヒープベースのバッファオーバーフローがあり、細工されたファイルを開くと任意コ
@joho_no_todai
19 Jul 2026
4297 Impressions
29 Retweets
68 Likes
14 Bookmarks
1 Reply
0 Quotes
Wordpress祭り中だけど、7-zip、こっちも地味に継続中。悪性書庫を開くだけのRCEは、さすがに放置できない。7-ZipはCVE-2026-14266を26.02で修正。細工したXZ chunked dataでheap-based buffer
@connect24h
19 Jul 2026
1232 Impressions
3 Retweets
19 Likes
9 Bookmarks
1 Reply
0 Quotes