DIRAS TAKE
Urgent: public exploit code is available, so prioritize mitigation now; treat exposed systems and users who open untrusted archives as high risk.
What is CVE-2026-14266?
An attacker can execute arbitrary code in 7-Zip by supplying specially crafted XZ-compressed data; this is tracked as CVE-2026-14266. The flaw affects 7-Zip 26.01 (26.x branch) and arises during XZ chunked data processing where a heap-based buffer overflow can be triggered. Exploitation requires user interaction: the target must open a malicious archive or visit a page that causes the application to process the crafted XZ data. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of 7-Zip 7-Zip are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 26.x | 26.01 |
Is CVE-2026-14266 being exploited?
Public exploit code is available.
How to fix CVE-2026-14266
- Do not open XZ-compressed files from untrusted sources and block delivery of such files where possible.
- Restrict 7-Zip exposure by limiting who can run it and which users can install or extract archives.
- Monitor endpoints for suspicious process activity and execution stemming from archive handling.
- Follow vendor guidance and apply a vendor-supplied update immediately when a patch is released.
Frequently asked questions
Is CVE-2026-14266 being actively exploited?
Public exploit code for CVE-2026-14266 is available as of 2026-09-29.
Which 7-Zip versions are affected by CVE-2026-14266?
7-Zip version 26.01 (26.x branch) is listed as affected by CVE-2026-14266.
Is there a patch for CVE-2026-14266?
There is no patch available for CVE-2026-14266 as of 2026-09-29.
Does CVE-2026-14266 require authentication?
CVE-2026-14266 does not require authentication but does require user interaction: a user must open a malicious file or visit a page that triggers processing of crafted XZ data.
References
- nvd.nist.gov/vuln/detail/CVE-2026-14266
- cve.org/CVERecord?id=CVE-2026-14266
- zerodayinitiative.com/advisories/ZDI-26-444
- All 7-Zip CVEs on CVE Radar
- CVEs published in September 2026