Security
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
The Hacker News·July 20, 2026·1 min read
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data. A fix shipped on June 25 in 7-Zip 26.02. Trend Micro's Zero Day Initiative detailed the vulnerability on July 15.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
