Find notable cyber news and cases, enriched with sources, timelines, and signals.

7-Zip XZ chunked data heap-based buffer overflow security flaw (CVE-2026-14266)

Vulnerability
First reported
Last updated
Happening score
H score 21
1 unique sources, 1 articles

Summary

Hide ▲

7-Zip's XZ chunked data parsing flaw, CVE-2026-14266, can let crafted archives trigger code execution in the current process. 7-Zip 26.02 fixed the issue on June 25, 2026. The bug is a heap-based buffer overflow in the archiver's XZ handling, and there is no public proof-of-concept or credible in-the-wild exploitation reported as of July 20, 2026. Users opening untrusted archives on affected systems face the main risk until patched builds are installed.

Related Happenings

Gamaredon Ukraine spear-phishing campaign across government and military targets

Campaign
H score39 First: 29.06.2026 14:40 Last: 29.06.2026 14:40 Sources 1

About this happening: The Gamaredon campaign expanded across Ukraine in 2025, hitting governmental and military institutions with 35 spear-phishing campaigns and raising the risk of...

Zombie ZIP archive-header evasion technique

Technical Analysis
H score24 First: 10.03.2026 22:05 Last: 10.03.2026 22:05 Sources 1

About this happening: Zombie ZIP is a new archive-evasion technique that can let payloads slip past AV and EDR scanning by abusing ZIP header parsing, making malicious content harder to detect....

Infy (aka Prince of Persia) renewed C2 campaign after Iran blackout

Campaign
H score17 First: 05.02.2026 12:25 Last: 05.02.2026 12:25 Sources 1

About this happening: Infy (aka Prince of Persia), an Iranian APT, is still running a covert campaign across Iran, Iraq, Turkey, India, Canada, and Europe using updated Foudre v34 and *...

Mustang Panda PlugX DOPLUGS deployment chain for persistent access

Malware Activity
H score26 First: 04.02.2026 16:09 Last: 04.02.2026 16:09 Sources 1

About this happening: Mustang Panda (TA416) used malicious ZIP/LNK chains to deliver its custom PlugX/DOPLUGS payload and maintain persistent access on compromised hosts. The activity t...

WinRAR path-traversal exploitation wave (CVE-2025-8088)

Exploitation Wave
H score20 First: 27.01.2026 21:38 Last: 27.01.2026 21:38 Sources 1

About this happening: CVE-2025-8088 in WinRAR remains an ongoing exploitation wave. Trend Micro says Russia-aligned groups Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-022...

Timeline

  1. 15.07.2026 03:00 2 articles · 6d ago

    ZDI details CVE-2026-14266 in 7-Zip's XZ chunked data handling

    Technical Analysis Update

    Trend Micro's Zero Day Initiative (ZDI) publishes technical details on CVE-2026-14266, describing the heap-based buffer overflow in 7-Zip's XZ chunked data handling and the code execution risk in the current process.

    Show sources