AI description
CVE-2026-14266 is a heap-based buffer overflow vulnerability found in 7-Zip, a widely used open-source file archiving tool. The flaw specifically arises from the improper handling of XZ chunked data during the decompression process. When 7-Zip processes specially crafted XZ-compressed data, it can trigger a memory corruption where data written to a buffer exceeds its allocated space. This vulnerability allows remote attackers to execute arbitrary code on affected systems. For exploitation, user interaction is required; a target must either open a maliciously crafted archive file or visit a malicious webpage designed to deliver the crafted XZ payload. Successful exploitation results in the execution of malicious code with the privileges of the logged-in user running 7-Zip. The issue has been addressed in 7-Zip version 26.02.
- Description
- 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.
- Source
- zdi-disclosures@trendmicro.com
- NVD status
- Analyzed
- Products
- 7-zip
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 3.0
- Type
- Secondary
- Base score
- 7
- Impact score
- 5.9
- Exploitability score
- 1
- Vector string
- CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- zdi-disclosures@trendmicro.com
- CWE-122
- Hype score
- Not currently trending
Update 7-Zip Now: CVE-2026-14266 Lets Attackers Run Code on Your PC #Cve #Update7ZipNow #Tech @CallofDuty https://t.co/hGbmbFwP3p
@HappyGamerNews
25 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
For defenders, 7-zip cve-2026-14266 turns archive handling into an endpoint pa… should move fast. ZDI disclosed CVE-2026-14266, a 7-Zip XZ decoder heap overflow fixed in 26.02 that can enab… 🔗 Details → https://t.co/AMysRhb3Ya
@SocXAInvaders
21 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️7-Zipがリモートコード実行の脆弱性を修正(CVE-2026-14266) 🚨WP2Shell脆弱性、攻撃で悪用されるように:CVE-2026-60137、CVE-2026-63030 〜サイバーセキュリティ週末の話題〜 https://t.co/bnTLCvEBEb
@MachinaRecord
21 Jul 2026
204 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
7-Zipに今年2件目のリモートコード実行脆弱性(CVE-2026-14266)が見つかった。CVSS 7.0。 XZ形式の圧縮データを展開する処理にヒープベースのバッファオーバーフローがあり、細工されたファイルを開くと任意コ
@joho_no_todai
19 Jul 2026
4297 Impressions
29 Retweets
68 Likes
14 Bookmarks
1 Reply
0 Quotes
Wordpress祭り中だけど、7-zip、こっちも地味に継続中。悪性書庫を開くだけのRCEは、さすがに放置できない。7-ZipはCVE-2026-14266を26.02で修正。細工したXZ chunked dataでheap-based buffer
@connect24h
19 Jul 2026
1232 Impressions
3 Retweets
19 Likes
9 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FCB07733-189C-477A-B66A-548C42B39D26",
"versionEndExcluding": "26.02",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]