7-zip Vulnerability Allows For Remote Code Execution​

A new heap-based buffer overflow vulnerability CVE-2026-14266 discovered in 7-zip could allow attackers to run arbitrary code if the user opens an arbitrary XZ archive. The flaw was rated high severity by Trend Micro's Zero Day Initiative. It was fixed in version 26.02 on June 25, 2026. On a normal Windows system, 7-zip by default runs with limited privileges, even on an administrator account—so any attacker is limited to those privileges when trying to run their malicious code. There is no public proof-of-concept code or active exploitation reported as of July 20, but users are still recommended to upgrade to version 26.06 soon.