256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction - The Hacker News

Share
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction - The Hacker News
Image · Internet

What the report says

The Hacker News reported that a newly detailed 7-Zip vulnerability could allow code execution when a user opens a specially crafted XZ archive. The flaw, tracked as CVE-2026-14266, is described as a high-severity heap-based buffer overflow in 7-Zip’s XZ decoder. Trend Micro’s Zero Day Initiative disclosed details on July 15, while 7-Zip had already released a fix on June 25 in version 26.02.

According to the report, the vulnerability was submitted by Landon Peng of Lunbun LLC, who reported it to 7-Zip on June 5. ZDI assigned it a CVSS 3.0 score of 7.0, rated High. The Hacker News noted that exploitation requires user interaction, such as opening an archive delivered by email, download or a web page, and that the issue is not a network-reachable, no-click flaw. Any malicious code would run with the privileges held by the 7-Zip process, not with automatic privilege escalation.

The report said the bug lies in the MixCoder_Code function in the XZ decoder source, where buffer length handling could allow an out-of-bounds write. Version 26.02 changes the handling to account for bytes already written and stop processing if limits are exceeded. The Hacker News said similar code appears in older releases going back to at least 2021, though it said neither ZDI nor 7-Zip had confirmed exactly which versions are exploitable.

The issue matters because 7-Zip is widely used to open archive files, including files obtained from outside an organization. The report said there was no public proof-of-concept or credible in-the-wild exploitation as of July 20, 2026, but recommended updating to 7-Zip 26.02 or later and checking products that bundle the vulnerable decoder.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting