The popular archiver 7-Zip has a security vulnerability that could allow attackers to inject and execute malicious code. Visiting a malicious website or opening a maliciously crafted file is sufficient.
Trend Micro's Zero-Day Initiative (ZDI) discovered and reported the vulnerability. A heap-based buffer overflow can occur when processing data in xz format. Attackers can exploit the vulnerability to execute malicious code in the context of the current process (CVE-2026-14266, CVSS 7.0, Risk “high”). The specific CVE vulnerability entry is not yet publicly available on cve.org or in NIST's NVD database at the time of reporting.
7-Zip: Updated software available
The updated version 7-Zip 26.02 is available for download for Linux, macOS, and Windows (ARM64, x64, and x86). The changelog only mentions some fixed bugs and vulnerabilities, the latter in plural. It is possible that more security vulnerabilities will become known that the update to version 26.02 fixes. Users and administrators should therefore not hesitate and update promptly.
In addition to manual download and installation, WinGet can also be used for updating. At the command prompt, the command winget upgrade --all must be executed. This updates not only 7-Zip but also other installed third-party software. Routine execution of this command helps minimize the system's attack surface.











