7-Zip patches a flaw that could run malware just from opening a bad file

https://www.techspot.com/images2/news/ts3_thumbs/2026/07/2026-07-20-ts3_thumbs-ed8.jpg

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

A Bug's Life: Because of its remarkable popularity, 7-Zip is a frequent target for cyber-criminals and security researchers alike, both hunting for new flaws to exploit. Luckily for users and busy sysadmins, its developers are usually quick to respond, shipping patched versions soon after issues surface.

Researchers have uncovered a fresh vulnerability in the open-source file archiver. The bug lies in the decompression routine for XZ data, where a buffer overflow could eventually let attackers run malicious code remotely. A patch is already out, though 7-Zip still has no built-in auto-update mechanism – users have to manually swap in the newer release themselves.

According to a write-up from Trend Micro's Zero Day Initiative, the flawtracked as CVE-2026-14266 is a heap-based buffer overflow. A specially crafted archive containing XZ-compressed data streams can...

Copyright of this story solely belongs to techspot.com. To see the full text click HERE

Read more