The popular archiver 7-Zip has a security vulnerability that could allow attackers to inject and execute malicious code. Visiting a malicious website or opening a maliciously crafted file is sufficient.
Trend Micro's Zero-Day Initiative (ZDI) discovered and reported the vulnerability . A heap-based buffer overflow can occur when processing data in xz format. Attackers can exploit the vulnerability to execute malicious code in the context of the current process (CVE-2026-14266, CVSS 7.0 , Risk “ high ”). The specific CVE vulnerability entry is not yet publicly available on cve.org or in NIST's NVD database at the time of reporting.
The updated version 7-Zip 26.02 is available for download for Linux, macOS, and Windows (ARM64, x64, and x86). The changelog only mentions some fixed bugs and vulnerabilities, the latter in plural. It is possible that more security vulnerabilities will become known that the update to version 26.02 fixes. Users and administrators should therefore not hesitate and update promptly.
In addition to manual download and installation, WinGet can also be used for updating. At the command prompt, the command winget upgrade --all must be executed. This updates not only 7-Zip but also other installed third-party software. Routine execution of this command helps minimize the system's attack surface.
Most recently, 7-Zip closed a high-risk security vulnerability at the end of May with the update to version 26.01. The error was in processing compressed NTFS streams. Manipulated data could cause 7-Zip to crash or lead to the execution of smuggled malicious code.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
