{"id":241249,"date":"2026-07-21T05:18:27","date_gmt":"2026-07-21T10:18:27","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/07\/new-7zip-vulnerability-could-let-crafted-xz-archives-run-code-during-extraction"},"modified":"2026-07-21T05:18:27","modified_gmt":"2026-07-21T10:18:27","slug":"new-7zip-vulnerability-could-let-crafted-xz-archives-run-code-during-extraction","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/07\/new-7zip-vulnerability-could-let-crafted-xz-archives-run-code-during-extraction","title":{"rendered":"New 7Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/new-7zip-vulnerability-could-let-crafted-xz-archives-run-code-during-extraction2.jpg\"><\/a><\/p>\n<p>26.02 subtracts the bytes already written and bails out if that running total ever exceeds the buffer. The same flawed length handling appears unchanged in 7-Zip source back to at least version 21.07 (2021), though neither ZDI nor 7-Zip has said which releases are actually exploitable.<\/p>\n<p>CVE-2026\u201314266 is the latest in a run of memory-safety bugs in 7-Zip\u2019s archive handlers. On April 27, version 26.01 fixed <a href=\"https:\/\/securitylab.github.com\/advisories\/GHSL-2026-115_GHSL-2026-122_7-zip\/\">a batch of them<\/a>, including the higher-scored <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-48095\">CVE-2026\u201348095<\/a>, an NTFS-handler heap-write overflow that <a href=\"https:\/\/securitylab.github.com\/advisories\/GHSL-2026-140_7-Zip\/\">GitHub Security Lab detailed<\/a> on May 22 with a working proof-of-concept. The XZ flaw is the quieter of the two so far, and 26.02 rolls up every one of these fixes, so one update covers them all.<\/p>\n<p>So update to 7-Zip 26.02 or later on every machine that opens archives from outside. Updating is a manual install from the official site, so set-and-forget machines will not pick it up on their own. Any product that ships a vulnerable copy of 7-Zip\u2019s XZ decoder needs its own vendor fix.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>26.02 subtracts the bytes already written and bails out if that running total ever exceeds the buffer. The same flawed length handling appears unchanged in 7-Zip source back to at least version 21.07 (2021), though neither ZDI nor 7-Zip has said which releases are actually exploitable. CVE-2026\u201314266 is the latest in a run of memory-safety [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1492],"tags":[],"class_list":["post-241249","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/241249","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=241249"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/241249\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=241249"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=241249"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=241249"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}