Opening a crafted XZ archive in 7-Zip could let an attacker
run code on the machine. The flaw, CVE-2026-14266, is a heap-based
buffer overflow in how the archiver processes XZ chunked data, and
Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A
fix shipped on June 25 in 7-Zip 26.02. The overflow lets an
attacker "execute code in the context of the current process," per
the
Read more https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html

