7-Zip 26.02 security update (CVE-2026-14266)
Security Patch Release
Summary
Hide ▲
Show ▼
7-Zip 26.02 shipped on June 25, 2026 to fix CVE-2026-14266, a heap-based buffer overflow in XZ chunked data handling that could let a crafted archive run code in the current process. The update gives users a patched build before the July 15 public advisory and reduces exposure for systems that open untrusted archives. Machines running 7-Zip still need to move to 26.02 or later because the fix is a manual install.
Related Happenings
Microsoft YellowKey patch release (CVE-2026-45585)
Security Patch Release
H score20
First: 11.06.2026 20:43
Last: 11.06.2026 20:43
Sources 1
About this happening:
Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...
Microsoft YellowKey patch release (CVE-2026-45585)
Security Patch ReleaseAbout this happening: Microsoft's Patch Tuesday updates this week patched YellowKey (CVE-2026-45585), closing a Windows BitLocker bypass that could expose protected volumes. The vendor rele...
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch Release
H score45
First: 22.05.2026 11:19
Last: 22.05.2026 11:19
Sources 1
About this happening:
TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch ReleaseAbout this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....
Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch Release
H score44
First: 21.05.2026 10:49
Last: 21.05.2026 10:49
Sources 1
About this happening:
Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...
Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498
Security Patch ReleaseAbout this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...
Latest development: 21.05.2026 12:52
Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.
Progress security patch release for CVE-2026-2699
Security Patch Release
H score68
First: 02.04.2026 16:33
Last: 02.04.2026 16:33
Sources 1
About this happening:
Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...
Progress security patch release for CVE-2026-2699
Security Patch ReleaseAbout this happening: Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update...
GIGABYTE security patch release for CVE-2026-4415
Security Patch Release
H score39
First: 01.04.2026 01:28
Last: 01.04.2026 01:28
Sources 1
About this happening:
GIGABYTE is directing users of Control Center to upgrade to 25.12.10.01 to mitigate CVE-2026-4415, a flaw that exposed systems to remote file writes. The update ma...
GIGABYTE security patch release for CVE-2026-4415
Security Patch ReleaseAbout this happening: GIGABYTE is directing users of Control Center to upgrade to 25.12.10.01 to mitigate CVE-2026-4415, a flaw that exposed systems to remote file writes. The update ma...
Timeline
-
20.07.2026 03:00 1 articles · 1d ago
No public proof-of-concept or in-the-wild exploitation appears by July 20, 2026
Untyped PhaseAs of July 20, 2026, no public proof-of-concept and no credible report of exploitation in the wild had surfaced for CVE-2026-14266.
Show sources
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10
-
15.07.2026 03:00 1 articles · 6d ago
ZDI details CVE-2026-14266 in 7-Zip
Technical Analysis UpdateTrend Micro's Zero Day Initiative (ZDI) detailed CVE-2026-14266 on July 15, describing the heap-based buffer overflow in 7-Zip's XZ chunked data handling and rating it 7.0 High with CVSS 3.0 vector AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H.
Show sources
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10
-
25.06.2026 03:00 2 articles · 26d ago
7-Zip ships version 26.02 to fix the XZ decoder overflow
Mitigation Patch Update7-Zip shipped version 26.02 on June 25 to fix CVE-2026-14266, closing the XZ decoder length-handling bug that could allow code execution when a crafted archive is opened.
Show sources
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10
-
05.06.2026 03:00 1 articles · 1mo ago
Landon Peng reports CVE-2026-14266 in 7-Zip
Initial DisclosureLandon Peng of Lunbun LLC reported CVE-2026-14266 to 7-Zip on June 5, describing a heap-based buffer overflow in XZ chunked data handling that could let a crafted archive execute code in the current process.
Show sources
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10