Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical 7-Zip Vulnerability Enables Code Execution

Critical 7-Zip Vulnerability Enables Code Execution

Posted on July 20, 2026 By CWS

A newly identified security flaw in the popular file archiving tool, 7-Zip, could allow attackers to execute arbitrary code during the extraction of specially crafted XZ archives. Identified as CVE-2026-14266, this vulnerability was initially detailed by Trend Micro’s Zero Day Initiative (ZDI) on July 15, 2026. The issue, a result of a heap-based buffer overflow, was addressed in the 7-Zip update version 26.02, which was released on June 25, 2026.

Understanding the Vulnerability

The vulnerability arises from the way 7-Zip handles XZ chunked data, allowing attackers to execute code with the same permissions as the 7-Zip process. According to the advisory, this does not inherently grant additional privileges beyond those of the current user, unless the application is executed with elevated permissions. The flaw was reported by Landon Peng of Lunbun LLC on June 5, 2026.

ZDI has rated the vulnerability with a severity score of 7.0, categorizing it as a ‘High’ risk. The flaw is classified as a local attack vector, meaning it requires the user to open the malicious file manually. This increases the complexity of executing the attack successfully, as the file must be delivered and opened by the victim through emails, downloads, or web pages.

Technical Analysis and Impact

The flaw was discovered during an analysis of the XZ decoder’s source code. The issue resided in the MixCoder_Code function within C/XzDec.c, where an out-of-bounds write condition was created. This occurred because the decoder was given more buffer space than was available, potentially allowing for arbitrary code execution.

Version 26.02 of 7-Zip addresses this by adjusting the buffer handling to prevent overflow, ensuring that the buffer is not exceeded. This vulnerability, along with others identified in previous updates, highlights ongoing concerns about memory safety in 7-Zip’s archive handling functions.

Recommendations and Future Outlook

Users are strongly advised to update to 7-Zip version 26.02 or later to safeguard against this and other vulnerabilities. Manual updates are necessary, as automatic updates are not available through the software, and any third-party products using the affected 7-Zip decoder should seek vendor-specific patches.

With the advisory released 20 days after the patch, users who updated promptly in late June were protected ahead of the public disclosure. This proactive approach is crucial in mitigating risks associated with such vulnerabilities, underscoring the importance of timely software updates in maintaining security.

The Hacker News Tags:7-Zip, buffer overflow, code execution, CVE-2026-14266, security patch, Software Security, Trend Micro, Vulnerability, XZ archive, Zero Day Initiative

Post navigation

Previous Post: Starbucks Data Allegedly Sold on Cybercrime Forum
Next Post: Capital One Releases AI Security Tool ‘VulnHunter’

Related Posts

CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog The Hacker News
New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora The Hacker News
Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra Blind Eagle’s Five Clusters Target Colombia Using RATs, Phishing Lures, and Dynamic DNS Infra The Hacker News
Checkmarx Data Breach: GitHub Data Exposed on Dark Web Checkmarx Data Breach: GitHub Data Exposed on Dark Web The Hacker News
Ousaban Trojan Targets Iberian Banks with PDF Traps Ousaban Trojan Targets Iberian Banks with PDF Traps The Hacker News
APT36 and SideCopy Target Indian Defense with RATs APT36 and SideCopy Target Indian Defense with RATs The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark