Researchers have uncovered a fresh vulnerability in the open-source file archiver. The bug lies in the decompression routine for XZ data, where a buffer overflow could eventually...

7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted…

CVE-2026-14266 is a high-severity heap overflow in 7-Zip’s XZ decoder that could run code when a user opens a crafted archive. Version 26.02 fixes it.