📣 Send us your press release
Site updates every 15 minutes
Technology

Critical Vulnerability in 7-Zip Allows Remote Code Execution; Update to 26.02

The widely used file compression utility 7-Zip has a critical vulnerability (CVE-2026-14266) that allows remote arbitrary code execution, but has been patched in version 26.02.

21 July 2026
Critical Vulnerability in 7-Zip Allows Remote Code Execution; Update to 26.02
Image is an AI-generated illustration

A critical security vulnerability has been discovered in the 7-Zip file compression utility, enabling attackers to execute arbitrary code remotely. The vulnerability, tracked as CVE-2026-14266 with a CVSS score of 7.0, stems from how the software processes XZ compressed files.

According to security researcher Zero Day Initiative (ZDI), the issue is a heap-based buffer overflow flaw that occurs when 7-Zip handles chunked data within XZ archives. An attacker can exploit this by tricking a user into opening a specially crafted XZ file, which could then allow them to run malicious code on the victim's system.

Developers have addressed the vulnerability in version 26.02 of 7-Zip, released on June 25. Users are strongly advised to update to this latest version immediately to mitigate security risks.

ZDI initially reported the vulnerability to 7-Zip developers on June 5. The disclosure followed ZDI's coordinated vulnerability disclosure process, with the report being made public on July 15. Users still on versions prior to 26.02 remain susceptible to exploitation.

Original source: ithome.com