ZDI-26-444 - TrendAI™ Zero Day Initiative™ (ZDI)
(from the old blog.html shell).<br>Swap this in if the full responsive set above causes background styling issues.
-->
Sign Up
Log In
Find us on
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
July 15th, 2026
ZDI-26-444<br>ZDI-CAN-30169
CVE ID
CVE-2026-14266
CVSS Score
7.0<br>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Vendors
7-Zip
Affected Products
7-Zip
Vulnerability Details
This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Additional Details
Fixed in 7-Zip 26.02
Disclosure Timeline
2026-06-05 - Vulnerability reported to vendor
2026-07-15 - Coordinated public release of advisory
2026-07-15 - Advisory Updated
Credit
Lunbun LLC (Landon Peng)
Back to Advisories
Stand at the front line of proactive security
TrendAI™ ZDI connects the experts who discover, remediate, and defend.<br>Add your voice to the work that pushes attackers back.
RESEARCHERS
Submit a vulnerability
VENDORS
Learn how it works
ORGANIZATIONS
See how you're protected