AntiMalware•July 17, 2026•🇷🇺Translated from Russian

7-Zip Vulnerability CVE-2026-14266 Enables Arbitrary Code Execution Through Malicious XZ Archives

A dangerous vulnerability has been discovered in the widely used file compression utility 7-Zip, identified as CVE-2026-14266. The flaw enables an attacker to execute arbitrary code on a victim’s system by tricking them into opening a specially prepared XZ archive.

The root cause lies in a buffer overflow that occurs during the processing of fragmented XZ data. When the application attempts to handle such malformed archives, it can write data outside the boundaries of allocated memory. Successful exploitation grants the attacker the ability to run malicious code with the same privileges as the current 7-Zip process.

Although the attack requires user participation, the vector is highly effective for phishing operations. Attackers can disguise the malicious file as a software update, backup archive, document package, or ordinary attachment delivered through messengers or email. Once opened, the payload may install malware, steal accessible data, modify files, or crash the system.

The vulnerability received a CVSS score of 7 out of 10. No authentication or prior access to the target device is required, increasing its potential severity in targeted scenarios. Researchers have not yet observed active exploitation of CVE-2026-14266 in the wild; however, technical details have already been published, providing a clear roadmap for threat actors seeking to develop working exploits.

Developers addressed the issue in 7-Zip 26.0. Security experts recommend that all users upgrade to the patched version without delay and avoid opening unexpected XZ archives from untrusted sources. Files bearing names such as “documents_important.xz” should be treated with particular caution, as they may contain not documents but actively malicious code.

Related articles

Habr•Vulnerabilities & Exploits

New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction

Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.

Security NEXT•Vulnerabilities & Exploits

Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score

Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.

Security NEXT•Vulnerabilities & Exploits

Fortinet Releases FortiMail Updates to Patch Zero-Day CVE-2026-104286

Fortinet has begun distributing updates for its FortiMail email security product to address the zero-day vulnerability CVE-2026-104286. The flaw allows unauthenticated attackers to write arbitrary files to the system by sending specially crafted HTTP requests. The company first published a security advisory on October 1, 2026, confirming active exploitation and providing Indicators of Compromise while preparing fixes. On October 5, 2026, Fortinet updated the advisory and released patched versions including FortiMail 8.0.2, 7.6.7, and 7.4.9. Organizations still running the 7.2 branch are advised to migrate to the 7.4 branch or later to obtain protection. The advisory reference is FG-IR-26-175.

Hispasec•Vulnerabilities & Exploits

Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution

A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.