Find notable cyber news and cases, enriched with sources, timelines, and signals.

7-Zip 26.02 security update (CVE-2026-14266)

Security Patch Release
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

7-Zip 26.02 shipped on June 25, 2026 to fix CVE-2026-14266, a heap-based buffer overflow in XZ chunked data handling that could let a crafted archive run code in the current process. The update gives users a patched build before the July 15 public advisory and reduces exposure for systems that open untrusted archives. Machines running 7-Zip still need to move to 26.02 or later because the fix is a manual install.

Related Happenings

Microsoft YellowKey patch release (CVE-2026-45585)

Security Patch Release
H score20 First: 11.06.2026 20:43 Last: 11.06.2026 20:43 Sources 1

About this happening: Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...

TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926

Security Patch Release
H score45 First: 22.05.2026 11:19 Last: 22.05.2026 11:19 Sources 1

About this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....

Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498

Security Patch Release
H score44 First: 21.05.2026 10:49 Last: 21.05.2026 10:49 Sources 1

About this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...

Latest development: 21.05.2026 12:52

Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.

Progress security patch release for CVE-2026-2699

Security Patch Release
H score68 First: 02.04.2026 16:33 Last: 02.04.2026 16:33 Sources 1

About this happening: Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...

GIGABYTE security patch release for CVE-2026-4415

Security Patch Release
H score39 First: 01.04.2026 01:28 Last: 01.04.2026 01:28 Sources 1

About this happening: GIGABYTE is directing users of Control Center to upgrade to 25.12.10.01 to mitigate CVE-2026-4415, a flaw that exposed systems to remote file writes. The update ma...

Timeline

  1. 15.07.2026 03:00 1 articles · 6d ago

    ZDI details CVE-2026-14266 in 7-Zip

    Technical Analysis Update

    Trend Micro's Zero Day Initiative (ZDI) detailed CVE-2026-14266 on July 15, describing the heap-based buffer overflow in 7-Zip's XZ chunked data handling and rating it 7.0 High with CVSS 3.0 vector AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H.

    Show sources
  2. 25.06.2026 03:00 2 articles · 26d ago

    7-Zip ships version 26.02 to fix the XZ decoder overflow

    Mitigation Patch Update

    7-Zip shipped version 26.02 on June 25 to fix CVE-2026-14266, closing the XZ decoder length-handling bug that could allow code execution when a crafted archive is opened.

    Show sources