Toggle light / dark theme

New 7Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

26.02 subtracts the bytes already written and bails out if that running total ever exceeds the buffer. The same flawed length handling appears unchanged in 7-Zip source back to at least version 21.07 (2021), though neither ZDI nor 7-Zip has said which releases are actually exploitable.

CVE-2026–14266 is the latest in a run of memory-safety bugs in 7-Zip’s archive handlers. On April 27, version 26.01 fixed a batch of them, including the higher-scored CVE-2026–48095, an NTFS-handler heap-write overflow that GitHub Security Lab detailed on May 22 with a working proof-of-concept. The XZ flaw is the quieter of the two so far, and 26.02 rolls up every one of these fixes, so one update covers them all.

So update to 7-Zip 26.02 or later on every machine that opens archives from outside. Updating is a manual install from the official site, so set-and-forget machines will not pick it up on their own. Any product that ships a vulnerable copy of 7-Zip’s XZ decoder needs its own vendor fix.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */