logo

7-Zip Vulnerability Lets Attackers Trigger Heap Buffer Overflow Using Malicious Files

ID: 3c85f4e3-64d7-5d6f-9489-a50f15f32a08

STIX ID: report--3c85f4e3-64d7-5d6f-9489-a50f15f32a08

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-07-17

Date Updated: 2026-07-21

Author: Divya

...
...

A heap-based buffer overflow (CVE-2026-14266, ZDI-26-444) in 7-Zip’s XZ chunked data processing can enable arbitrary code execution if a user opens a malicious archive; the flaw carries a CVSS of 7.0, requires user interaction, no active exploitation has been reported, and a patch is available in 7-Zip v26.0 (users should update and avoid opening untrusted XZ archives).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.