7-Zip XZ chunked data heap-based buffer overflow security flaw (CVE-2026-14266)
Vulnerability
Summary
Hide ▲
Show ▼
7-Zip's XZ chunked data parsing flaw, CVE-2026-14266, can let crafted archives trigger code execution in the current process. 7-Zip 26.02 fixed the issue on June 25, 2026. The bug is a heap-based buffer overflow in the archiver's XZ handling, and there is no public proof-of-concept or credible in-the-wild exploitation reported as of July 20, 2026. Users opening untrusted archives on affected systems face the main risk until patched builds are installed.
Related Happenings
Gamaredon Ukraine spear-phishing campaign across government and military targets
Campaign
H score39
First: 29.06.2026 14:40
Last: 29.06.2026 14:40
Sources 1
About this happening:
The Gamaredon campaign expanded across Ukraine in 2025, hitting governmental and military institutions with 35 spear-phishing campaigns and raising the risk of...
Gamaredon Ukraine spear-phishing campaign across government and military targets
CampaignAbout this happening: The Gamaredon campaign expanded across Ukraine in 2025, hitting governmental and military institutions with 35 spear-phishing campaigns and raising the risk of...
Zombie ZIP archive-header evasion technique
Technical Analysis
H score24
First: 10.03.2026 22:05
Last: 10.03.2026 22:05
Sources 1
About this happening:
Zombie ZIP is a new archive-evasion technique that can let payloads slip past AV and EDR scanning by abusing ZIP header parsing, making malicious content harder to detect....
Zombie ZIP archive-header evasion technique
Technical AnalysisAbout this happening: Zombie ZIP is a new archive-evasion technique that can let payloads slip past AV and EDR scanning by abusing ZIP header parsing, making malicious content harder to detect....
Infy (aka Prince of Persia) renewed C2 campaign after Iran blackout
Campaign
H score17
First: 05.02.2026 12:25
Last: 05.02.2026 12:25
Sources 1
About this happening:
Infy (aka Prince of Persia), an Iranian APT, is still running a covert campaign across Iran, Iraq, Turkey, India, Canada, and Europe using updated Foudre v34 and *...
Infy (aka Prince of Persia) renewed C2 campaign after Iran blackout
CampaignAbout this happening: Infy (aka Prince of Persia), an Iranian APT, is still running a covert campaign across Iran, Iraq, Turkey, India, Canada, and Europe using updated Foudre v34 and *...
Mustang Panda PlugX DOPLUGS deployment chain for persistent access
Malware Activity
H score26
First: 04.02.2026 16:09
Last: 04.02.2026 16:09
Sources 1
About this happening:
Mustang Panda (TA416) used malicious ZIP/LNK chains to deliver its custom PlugX/DOPLUGS payload and maintain persistent access on compromised hosts. The activity t...
Mustang Panda PlugX DOPLUGS deployment chain for persistent access
Malware ActivityAbout this happening: Mustang Panda (TA416) used malicious ZIP/LNK chains to deliver its custom PlugX/DOPLUGS payload and maintain persistent access on compromised hosts. The activity t...
WinRAR path-traversal exploitation wave (CVE-2025-8088)
Exploitation Wave
H score20
First: 27.01.2026 21:38
Last: 27.01.2026 21:38
Sources 1
About this happening:
CVE-2025-8088 in WinRAR remains an ongoing exploitation wave. Trend Micro says Russia-aligned groups Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-022...
WinRAR path-traversal exploitation wave (CVE-2025-8088)
Exploitation WaveAbout this happening: CVE-2025-8088 in WinRAR remains an ongoing exploitation wave. Trend Micro says Russia-aligned groups Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-022...
Timeline
-
20.07.2026 12:10 1 articles · 16h ago
Landon Peng reports the 7-Zip XZ chunked data overflow
Initial DisclosureLandon Peng of Lunbun LLC reports the heap-based buffer overflow in 7-Zip's XZ chunked data handling to the vendor, initiating disclosure for the flaw later identified as CVE-2026-14266.
Show sources
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10
-
20.07.2026 12:10 1 articles · 16h ago
7-Zip ships version 26.02 to fix CVE-2026-14266
Mitigation Patch Update7-Zip releases version 26.02, closing CVE-2026-14266 in the XZ chunked data decoder after the heap-based buffer overflow was identified.
Show sources
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10
-
15.07.2026 03:00 2 articles · 6d ago
ZDI details CVE-2026-14266 in 7-Zip's XZ chunked data handling
Technical Analysis UpdateTrend Micro's Zero Day Initiative (ZDI) publishes technical details on CVE-2026-14266, describing the heap-based buffer overflow in 7-Zip's XZ chunked data handling and the code execution risk in the current process.
Show sources
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — thehackernews.com — 20.07.2026 12:10