Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
The Hacker News
3 weeks ago

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

By info@thehackernews.com (The Hacker News)

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.