logo

CVE-2026-14266: 7-Zip Heap Overflow Flaw Can Lead to Remote Code Execution

ID: aa14bb50-e651-5672-b0fd-5e8867c0a11e

STIX ID: report--aa14bb50-e651-5672-b0fd-5e8867c0a11e

Feed Name: SOC Prime Blog

Threat Score
65/100

Date Published: 2026-07-23

Date Updated: 2026-07-25

Author: SOC Prime Team

...
...

CVE-2026-14266 is a heap-based buffer overflow in 7-Zip's XZ handling that can enable arbitrary code execution when a user processes crafted archive content; the advisory urges immediate updates to 7-Zip 26.02 or later, outlines detection and mitigation steps (inventorying vulnerable versions, user guidance, attachment scanning), and notes no public PoC or IOCs were available at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.