Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical 7-Zip Vulnerability Enables Code Execution

Critical 7-Zip Vulnerability Enables Code Execution

Posted on July 20, 2026 By CWS

A newly identified security flaw in the popular file archiving tool, 7-Zip, could allow attackers to execute arbitrary code during the extraction of specially crafted XZ archives. Identified as CVE-2026-14266, this vulnerability was initially detailed by Trend Micro’s Zero Day Initiative (ZDI) on July 15, 2026. The issue, a result of a heap-based buffer overflow, was addressed in the 7-Zip update version 26.02, which was released on June 25, 2026.

Understanding the Vulnerability

The vulnerability arises from the way 7-Zip handles XZ chunked data, allowing attackers to execute code with the same permissions as the 7-Zip process. According to the advisory, this does not inherently grant additional privileges beyond those of the current user, unless the application is executed with elevated permissions. The flaw was reported by Landon Peng of Lunbun LLC on June 5, 2026.

ZDI has rated the vulnerability with a severity score of 7.0, categorizing it as a ‘High’ risk. The flaw is classified as a local attack vector, meaning it requires the user to open the malicious file manually. This increases the complexity of executing the attack successfully, as the file must be delivered and opened by the victim through emails, downloads, or web pages.

Technical Analysis and Impact

The flaw was discovered during an analysis of the XZ decoder’s source code. The issue resided in the MixCoder_Code function within C/XzDec.c, where an out-of-bounds write condition was created. This occurred because the decoder was given more buffer space than was available, potentially allowing for arbitrary code execution.

Version 26.02 of 7-Zip addresses this by adjusting the buffer handling to prevent overflow, ensuring that the buffer is not exceeded. This vulnerability, along with others identified in previous updates, highlights ongoing concerns about memory safety in 7-Zip’s archive handling functions.

Recommendations and Future Outlook

Users are strongly advised to update to 7-Zip version 26.02 or later to safeguard against this and other vulnerabilities. Manual updates are necessary, as automatic updates are not available through the software, and any third-party products using the affected 7-Zip decoder should seek vendor-specific patches.

With the advisory released 20 days after the patch, users who updated promptly in late June were protected ahead of the public disclosure. This proactive approach is crucial in mitigating risks associated with such vulnerabilities, underscoring the importance of timely software updates in maintaining security.

The Hacker News Tags:7-Zip, buffer overflow, code execution, CVE-2026-14266, security patch, Software Security, Trend Micro, Vulnerability, XZ archive, Zero Day Initiative

Post navigation

Previous Post: Starbucks Data Allegedly Sold on Cybercrime Forum
Next Post: Capital One Releases AI Security Tool ‘VulnHunter’

Related Posts

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise The Hacker News
Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools The Hacker News
Cyber Espionage Threatens Asian Infrastructure via Web Exploits Cyber Espionage Threatens Asian Infrastructure via Web Exploits The Hacker News
AI Advances Challenge Traditional MDR Security Models AI Advances Challenge Traditional MDR Security Models The Hacker News
New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT The Hacker News
ENCFORGE Ransomware Hits AI Files in Langflow Attack ENCFORGE Ransomware Hits AI Files in Langflow Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark