A heap‑based buffer overflow in 7‑Zip's XZ decoder (CVE‑2026‑14266) allows remote code execution when a crafted XZ archive is opened. Patch 7‑Zip 26.02 mitigates the issue.

7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted…

CVE-2026-14266 is a high-severity heap overflow in 7-Zip’s XZ decoder that could run code when a user opens a crafted archive. Version 26.02 fixes it.

A heap‑based buffer overflow in 7‑Zip's XZ decoder (CVE‑2026‑14266) allows remote code execution when a crafted XZ archive is opened. Patch 7‑Zip 26.02 mitigates the issue.

Researchers have uncovered a fresh vulnerability in the open-source file archiver. The bug lies in the decompression routine for XZ data, where a buffer overflow could…

Una falla nel decoder XZ di 7-Zip può causare esecuzione di codice. Come funziona la falla CVE-2026-14266 e perché aggiornare alla 26.02.