CuraSec

Act archived

7-Zip CVE-2026-14266: XZ Archive Heap Overflow Enables Code Execution

2026-07-20 13:16 UTC · The Hacker News · read the source ↗ #vulnerability#code-execution#supply-chain
  • Engineer — Act: Public PoC exists for a heap overflow triggered by opening a crafted XZ archive in 7-Zip, a tool common in dev workstations and CI/CD pipelines; patch all 7-Zip installations to 26.02 and audit any automated pipeline steps that extract XZ archives unattended.
  • SOC/IR — Plan: No confirmed in-the-wild exploitation yet, but the public PoC raises urgency; build a detection for anomalous child processes spawned from 7-Zip binaries (7z.exe, 7zG.exe) during extraction, prioritizing CI/CD runners and build servers where archives are processed automatically.
  • Leader — Skip
  • Signals: CVE-2026-14266 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.