Sploitus

CVE-2026-14266

2 known exploits for CVE-2026-14266

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.

Affected products
7-Zip
7-zip
< 26.02
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
0.9% (58th percentile)
Weakness
CWE-122
NVD status
Analyzed
Published
2026-07-29
CVE-2026-14266 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-14266

Proof-of-concept code and exploit modules indexed by Sploitus