Summary
7-Zip version 26.02 patched a high-severity remote code execution vulnerability (CVE-2026-14266) caused by a heap-based buffer overflow in its XZ decompression logic. Attackers can exploit this flaw via malicious archives to take control of user systems. Manual updates are required as the software lacks auto-update features.
Take Action:
Update 7-Zip manually to version 26.02 ASAP by downloading it from the official website (7-zip.org), since 7-Zip cannot update itself. Until you've updated, don't open archive files from emails or unknown sources, as one malicious file is enough to let attackers take over your session.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)