This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Recently Discovered 7-Zip Archiving Vulnerability
The recently discovered 7-Zip archiving vulnerability (CVE-2026-14266) allows attackers to remotely execute arbitrary code on affected systems. When a user opens a maliciously crafted archive or visits a malicious web page delivering specially prepared files, a heap buffer overflow can be triggered, enabling code execution with user privileges. Such vulnerabilities are typically exploited in phishing campaigns to gain initial access or deliver ransomware. The vulnerability has been fixed in 7-Zip version 26.02; therefore, all versions up to 26.02 are affected. Since 7-Zip does not have automatic updates, it is recommended to ensure the software is manually updated to at least version 26.02. https://cybersecuritynews.com/7-zip-vulnerability-code-execution/