• PoC PUBLIC

CVE-2026-14266: remote code execution in 7-Zip 7-Zip

An attacker can execute arbitrary code in 7-Zip by supplying specially crafted XZ-compressed data; this is tracked as CVE-2026-14266. The flaw affects 7-Zip 26.01 (26.x branch) and arises during XZ chunked data processing where a heap-based buffer overflow can be triggered. Exploitation requires user interaction: the target must open a malicious archive or visit a page that causes the application to process the crafted XZ data.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.8HIGH
EPSS
0.00742
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code is available, so prioritize mitigation now; treat exposed systems and users who open untrusted archives as high risk.

What is CVE-2026-14266?

An attacker can execute arbitrary code in 7-Zip by supplying specially crafted XZ-compressed data; this is tracked as CVE-2026-14266. The flaw affects 7-Zip 26.01 (26.x branch) and arises during XZ chunked data processing where a heap-based buffer overflow can be triggered. Exploitation requires user interaction: the target must open a malicious archive or visit a page that causes the application to process the crafted XZ data. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of 7-Zip 7-Zip are affected?

BRANCHAFFECTEDFIXED
26.x26.01

Is CVE-2026-14266 being exploited?

Public exploit code is available.

How to fix CVE-2026-14266

  1. Do not open XZ-compressed files from untrusted sources and block delivery of such files where possible.
  2. Restrict 7-Zip exposure by limiting who can run it and which users can install or extract archives.
  3. Monitor endpoints for suspicious process activity and execution stemming from archive handling.
  4. Follow vendor guidance and apply a vendor-supplied update immediately when a patch is released.

Frequently asked questions

Is CVE-2026-14266 being actively exploited?

Public exploit code for CVE-2026-14266 is available as of 2026-09-29.

Which 7-Zip versions are affected by CVE-2026-14266?

7-Zip version 26.01 (26.x branch) is listed as affected by CVE-2026-14266.

Is there a patch for CVE-2026-14266?

There is no patch available for CVE-2026-14266 as of 2026-09-29.

Does CVE-2026-14266 require authentication?

CVE-2026-14266 does not require authentication but does require user interaction: a user must open a malicious file or visit a page that triggers processing of crafted XZ data.

References