← Back to feed
vulnerabilities1 source · 2h ago

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Trend Micro's Zero Day Initiative disclosed CVE-2026-14266, a heap-based buffer overflow vulnerability in 7-Zip's XZ archive handler that allows code execution during extraction, prompting a fix in version 26.02.

Affected 7-Zip CVE-2026-14266 CVE-2026-48095 GitHub Security Lab Landon Peng Lunbun LLC Trend Micro Zero Day Initiative

No Reader read of this story yet.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

Perspective analysis pending — it generates as coverage from more origins arrives.

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

Impact analysis pending.

Sources (1)

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — Prism