7-Zip version 26.02 and prior versions are affected by a heap-based buffer overflow vulnerability (CVE-2026-14266) in XZ archive decompression and a Mark-of-the-Web (MotW) bypass flaw (CVE-2026-58052). An attacker can potentially achieve remote code execution if a user opens a maliciously crafted XZ or RAR5 archive.Vulnerability DetailsCVE-2026-14266: Heap-based buffer overflow in XZ chunked data handling with a CVSS score of 7.0; triggered when opening a fake compressed file.CVE-2026-58052: Mark-of-the-Web...
qualsys has flagged this version as unsafe, is there a fix eta? 7-Zip version 26.02 and prior versions are affected by a heap-based buffer overflow vulnerability (CVE-2026-14266) in XZ archive decompression and a Mark-of-the-Web (MotW) bypass flaw (CVE-2026-58052). An attacker can potentially achieve remote code execution if a user opens a maliciously crafted XZ or RAR5 archive.Vulnerability DetailsCVE-2026-14266: Heap-based buffer overflow in XZ chunked data handling with a CVSS score of 7.0; triggered...