
7-Zip XZ Decoder Overflow Could Let Crafted Archives Execute Code
A heap-based buffer overflow in 7-Zip’s XZ decoding pipeline (CVE-2026-14266) can trigger when processing crafted XZ data, allowing code execution within the 7-Zip process. The fix in 7-Zip 26.02 corrects how remaining buffer space is tracked to prevent out-of-bounds writes. It’s a local attack vector requiring the user to open the file, with Windows processes typically running under limited rights, mitigating potential impact. ZDI rates the flaw as High (7.0); as of July 20, 2026, no public PoC or exploitation in the wild is known. Users should manually update to 7-Zip 26.02 or later on all machines, since the patch was released before disclosure and won’t auto-install on stand-alone systems.



