New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.

The overflow lets an attacker “execute code in the context of the current process,” per the

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

GLM-5.3: Frontier coding with emergent cyber capabilities

GLM-5.3: Frontier coding with emergent cyber capabilities Source: Hacker News

Airbus Full Scale Foldable Wing Extensions

Airbus Full Scale Foldable Wing Extensions Source: Hacker News

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated