High severity7.8NVD Advisory· Published Jul 29, 2026· Updated Aug 7, 2026
CVE-2026-14266
CVE-2026-14266
Description
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/7zip&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/7zip&distro=openSUSE%20Tumbleweed
< 26.02-160000.1.1+ 1 more
- (no CPE)range: < 26.02-160000.1.1
- (no CPE)range: < 26.02-1.1
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/07/17/12nvdMailing ListThird Party Advisory
- www.zerodayinitiative.com/advisories/ZDI-26-444/nvdThird Party AdvisoryVDB Entry
News mentions
4- Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 StoriesCyber Security News · Jul 26, 2026
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThe Hacker News · Jul 20, 2026
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During ExtractionThe Hacker News · Jul 20, 2026
- 7-Zip Vulnerability Exposes Millions of Users to Remote Code Execution RiskCyber Security News · Jul 17, 2026