7-Zip XZ Decompression Heap-Based Buffer Overflow RCE Vulnerability

exploraz1 pts0 comments

ZDI-26-444 - TrendAI™ Zero Day Initiative™ (ZDI)

(from the old blog.html shell).<br>Swap this in if the full responsive set above causes background styling issues.

-->

Sign Up

Log In

Find us on

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

July 15th, 2026

ZDI-26-444<br>ZDI-CAN-30169

CVE ID

CVE-2026-14266

CVSS Score

7.0<br>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Vendors

7-Zip

Affected Products

7-Zip

Vulnerability Details

This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

Additional Details

Fixed in 7-Zip 26.02

Disclosure Timeline

2026-06-05 - Vulnerability reported to vendor

2026-07-15 - Coordinated public release of advisory

2026-07-15 - Advisory Updated

Credit

Lunbun LLC (Landon Peng)

Back to Advisories

Stand at the front line of proactive security

TrendAI™ ZDI connects the experts who discover, remediate, and defend.<br>Add your voice to the work that pushes attackers back.

RESEARCHERS

Submit a vulnerability

VENDORS

Learn how it works

ORGANIZATIONS

See how you're protected

vulnerability heap based buffer overflow code

Related Articles