New 7-Zip Vulnerability CVE-2026-14266 Allows Code Execution via Crafted XZ Archives
A critical vulnerability in 7-Zip, identified as CVE-2026-14266, allows attackers to execute arbitrary code by tricking users into opening a specially crafted…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
A critical vulnerability in 7-Zip, identified as CVE-2026-14266, allows attackers to execute arbitrary code by tricking users into opening a specially crafted…
CVE-2026-14266 is a heap-based buffer overflow vulnerability in 7-Zip's XZ decoder, specifically in the MixCoder_Code function. It allows an attacker to execute…
CVE-2026-48095 is a heap-write overflow vulnerability in 7-Zip's NTFS handler, fixed in version 26.01. It was detailed by GitHub Security Lab with…
A heap buffer overflow in NGINX's script engine allows unauthenticated remote attackers to crash worker processes or potentially execute arbitrary code. Affects…
A heap overflow in NGINX's rewrite module due to overlapping captures, disclosed in May 2026. Similar class of flaw as CVE-2026-42533, involving…
F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow…
A previously undocumented threat actor, tracked as UTA0533 by Volexity, exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series…
A critical unauthenticated remote code execution vulnerability has been discovered in WordPress core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.…
A critical vulnerability in WordPress core allows unauthenticated remote code execution through a REST API batch-route confusion and SQL injection issue. Affects…
Okta's Red Team has disclosed a denial-of-service vulnerability in OpenSSL, dubbed HollowByte, that allows an attacker to freeze server memory using 11-byte…