
Critical 7-Zip XZ Vulnerability Allows Remote Code Execution via Malicious Files
A critical heap-based buffer overflow vulnerability in 7-Zip, the widely used open-source file archiver, could allow remote attackers to execute arbitrary code on affected systems. Tracked as CVE-2026-14266, the flaw resides in 7-Zip’s handling of XZ chunked data during decompression. Specifically, crafted XZ-compressed data can trigger a heap-based buffer overflow, allowing attackers to execute code […]
The post Critical 7-Zip XZ Vulnerability Allows Remote Code Execution via Malicious Files appeared first on Cyber Security News.