{"schema_version":1,"title":"7-Zip vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in 7-Zip: 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-14266, was published on 29 July 2026.","url":"https://junglewise.ai/threats/technologies/7-zip","json_url":"https://junglewise.ai/threats/technologies/7-zip.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/7-zip","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":12,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":10},"latest":[{"cve":"CVE-2026-14266","cvss":7,"slug":"cve-2026-14266-7-zip-heap-overflow-in-xz-decompression","title":"7-Zip heap overflow in XZ decompression","severity":"high","exploited":false,"published_at":"2026-07-29T18:16:50.72+00:00","url":"https://junglewise.ai/threats/cve-2026-14266-7-zip-heap-overflow-in-xz-decompression"},{"cve":"CVE-2026-58052","cvss":3.3,"slug":"cve-2026-58052-7-zip-mark-of-the-web-bypass-in-rar5-extraction","title":"7-Zip Mark-of-the-Web bypass in RAR5 extraction","severity":"low","exploited":false,"published_at":"2026-06-28T02:16:32.283+00:00","url":"https://junglewise.ai/threats/cve-2026-58052-7-zip-mark-of-the-web-bypass-in-rar5-extraction"},{"cve":"CVE-2026-48112","cvss":6.5,"slug":"cve-2026-48112-7-zip-heap-out-of-bounds-read-in-ar-and-squashfs-handlers","title":"7-Zip heap out-of-bounds read in Ar and SquashFS handlers","severity":"medium","exploited":false,"published_at":"2026-06-05T17:16:49.353+00:00","url":"https://junglewise.ai/threats/cve-2026-48112-7-zip-heap-out-of-bounds-read-in-ar-and-squashfs-handlers"},{"cve":"CVE-2026-48111","cvss":4.3,"slug":"cve-2026-48111-7-zip-out-of-bounds-read-in-uefi-firmware-image-parser","title":"7-Zip out-of-bounds read in UEFI firmware image parser","severity":"medium","exploited":false,"published_at":"2026-06-05T17:16:48.937+00:00","url":"https://junglewise.ai/threats/cve-2026-48111-7-zip-out-of-bounds-read-in-uefi-firmware-image-parser"},{"cve":"CVE-2026-48104","cvss":4.2,"slug":"cve-2026-48104-7-zip-uninitialized-heap-read-in-squashfs-handler","title":"7-Zip uninitialized heap read in SquashFS handler","severity":"medium","exploited":false,"published_at":"2026-06-05T17:16:48.547+00:00","url":"https://junglewise.ai/threats/cve-2026-48104-7-zip-uninitialized-heap-read-in-squashfs-handler"},{"cve":"CVE-2026-48103","cvss":4.3,"slug":"cve-2026-48103-7-zip-heap-out-of-bounds-read-in-wim-archive-handler","title":"7-Zip heap out-of-bounds read in WIM archive handler","severity":"medium","exploited":false,"published_at":"2026-06-05T17:16:48.133+00:00","url":"https://junglewise.ai/threats/cve-2026-48103-7-zip-heap-out-of-bounds-read-in-wim-archive-handler"},{"cve":"CVE-2026-48102","cvss":3.1,"slug":"cve-2026-48102-7-zip-heap-out-of-bounds-read-in-udf-disc-image-handler","title":"7-Zip heap out-of-bounds read in UDF disc image handler","severity":"low","exploited":false,"published_at":"2026-06-05T16:16:41.593+00:00","url":"https://junglewise.ai/threats/cve-2026-48102-7-zip-heap-out-of-bounds-read-in-udf-disc-image-handler"},{"cve":"CVE-2026-48101","cvss":6.5,"slug":"cve-2026-48101-7-zip-uninitialized-memory-disclosure-in-uefi-capsule-parser","title":"7-Zip uninitialized memory disclosure in UEFI capsule parser","severity":"medium","exploited":false,"published_at":"2026-06-05T16:16:41.423+00:00","url":"https://junglewise.ai/threats/cve-2026-48101-7-zip-uninitialized-memory-disclosure-in-uefi-capsule-parser"},{"cve":"CVE-2026-48095","cvss":8.8,"slug":"cve-2026-48095-7-zip-heap-buffer-overflow-in-ntfs-handler","title":"7-Zip heap buffer overflow in NTFS handler","severity":"high","exploited":false,"published_at":"2026-06-05T15:16:53.52+00:00","url":"https://junglewise.ai/threats/cve-2026-48095-7-zip-heap-buffer-overflow-in-ntfs-handler"},{"cve":"CVE-2026-48092","cvss":4.3,"slug":"cve-2026-48092-7-zip-heap-memory-disclosure-in-squashfs-readblock","title":"7-Zip heap memory disclosure in SquashFS ReadBlock","severity":"medium","exploited":false,"published_at":"2026-06-05T15:16:53.38+00:00","url":"https://junglewise.ai/threats/cve-2026-48092-7-zip-heap-memory-disclosure-in-squashfs-readblock"},{"cve":"CVE-2025-53816","cvss":7.5,"slug":"cve-2025-53816-7-zip-heap-buffer-overflow-in-rar5-handler","title":"7-Zip heap buffer overflow in RAR5 handler","severity":"high","exploited":false,"published_at":"2025-07-17T19:15:25.17+00:00","url":"https://junglewise.ai/threats/cve-2025-53816-7-zip-heap-buffer-overflow-in-rar5-handler"},{"cve":"CVE-2025-0411","cvss":7,"slug":"cve-2025-0411-7-zip-mark-of-the-web-bypass-vulnerability","title":"7-Zip Mark of the Web Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-06T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-0411-7-zip-mark-of-the-web-bypass-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"7-Zip","slug":"7-zip","vendor":{"name":"7-Zip","slug":"7-zip","url":"https://junglewise.ai/threats/vendors/7-zip"},"aliases":[],"category":"archiver","homepage":"https://www.7-zip.org/","repo_url":"https://sourceforge.net/projects/sevenzip/","description":"7-Zip is a free and open-source file archiver used to compress and unpack files in various formats.","url":"https://junglewise.ai/threats/technologies/7-zip"},"most_severe":[{"cve":"CVE-2025-0411","cvss":7,"slug":"cve-2025-0411-7-zip-mark-of-the-web-bypass-vulnerability","title":"7-Zip Mark of the Web Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-06T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-0411-7-zip-mark-of-the-web-bypass-vulnerability"},{"cve":"CVE-2026-48095","cvss":8.8,"slug":"cve-2026-48095-7-zip-heap-buffer-overflow-in-ntfs-handler","title":"7-Zip heap buffer overflow in NTFS handler","severity":"high","exploited":false,"published_at":"2026-06-05T15:16:53.52+00:00","url":"https://junglewise.ai/threats/cve-2026-48095-7-zip-heap-buffer-overflow-in-ntfs-handler"},{"cve":"CVE-2025-53816","cvss":7.5,"slug":"cve-2025-53816-7-zip-heap-buffer-overflow-in-rar5-handler","title":"7-Zip heap buffer overflow in RAR5 handler","severity":"high","exploited":false,"published_at":"2025-07-17T19:15:25.17+00:00","url":"https://junglewise.ai/threats/cve-2025-53816-7-zip-heap-buffer-overflow-in-rar5-handler"},{"cve":"CVE-2026-14266","cvss":7,"slug":"cve-2026-14266-7-zip-heap-overflow-in-xz-decompression","title":"7-Zip heap overflow in XZ decompression","severity":"high","exploited":false,"published_at":"2026-07-29T18:16:50.72+00:00","url":"https://junglewise.ai/threats/cve-2026-14266-7-zip-heap-overflow-in-xz-decompression"},{"cve":"CVE-2026-48112","cvss":6.5,"slug":"cve-2026-48112-7-zip-heap-out-of-bounds-read-in-ar-and-squashfs-handlers","title":"7-Zip heap out-of-bounds read in Ar and SquashFS handlers","severity":"medium","exploited":false,"published_at":"2026-06-05T17:16:49.353+00:00","url":"https://junglewise.ai/threats/cve-2026-48112-7-zip-heap-out-of-bounds-read-in-ar-and-squashfs-handlers"},{"cve":"CVE-2026-48101","cvss":6.5,"slug":"cve-2026-48101-7-zip-uninitialized-memory-disclosure-in-uefi-capsule-parser","title":"7-Zip uninitialized memory disclosure in UEFI capsule parser","severity":"medium","exploited":false,"published_at":"2026-06-05T16:16:41.423+00:00","url":"https://junglewise.ai/threats/cve-2026-48101-7-zip-uninitialized-memory-disclosure-in-uefi-capsule-parser"},{"cve":"CVE-2026-48111","cvss":4.3,"slug":"cve-2026-48111-7-zip-out-of-bounds-read-in-uefi-firmware-image-parser","title":"7-Zip out-of-bounds read in UEFI firmware image parser","severity":"medium","exploited":false,"published_at":"2026-06-05T17:16:48.937+00:00","url":"https://junglewise.ai/threats/cve-2026-48111-7-zip-out-of-bounds-read-in-uefi-firmware-image-parser"},{"cve":"CVE-2026-48103","cvss":4.3,"slug":"cve-2026-48103-7-zip-heap-out-of-bounds-read-in-wim-archive-handler","title":"7-Zip heap out-of-bounds read in WIM archive handler","severity":"medium","exploited":false,"published_at":"2026-06-05T17:16:48.133+00:00","url":"https://junglewise.ai/threats/cve-2026-48103-7-zip-heap-out-of-bounds-read-in-wim-archive-handler"},{"cve":"CVE-2026-48092","cvss":4.3,"slug":"cve-2026-48092-7-zip-heap-memory-disclosure-in-squashfs-readblock","title":"7-Zip heap memory disclosure in SquashFS ReadBlock","severity":"medium","exploited":false,"published_at":"2026-06-05T15:16:53.38+00:00","url":"https://junglewise.ai/threats/cve-2026-48092-7-zip-heap-memory-disclosure-in-squashfs-readblock"},{"cve":"CVE-2026-48104","cvss":4.2,"slug":"cve-2026-48104-7-zip-uninitialized-heap-read-in-squashfs-handler","title":"7-Zip uninitialized heap read in SquashFS handler","severity":"medium","exploited":false,"published_at":"2026-06-05T17:16:48.547+00:00","url":"https://junglewise.ai/threats/cve-2026-48104-7-zip-uninitialized-heap-read-in-squashfs-handler"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}