Tag
#Code Execution
blogHIGH 8.0
Understanding the 7-Zip Vulnerability: CVE-2026-14266
A new vulnerability in 7-Zip, CVE-2026-14266, allows attackers to execute code on a machine by crafting a malicious XZ archive. This heap-based buffer overflow flaw occurs during the processing of XZ chunked data. A fix was released on June 25 in 7-Zip version 26.02. Understanding this vulnerability is crucial for defenders to protect against potential code execution attacks.
newsCRITICAL 9.6
Critical Path Traversal Vulnerability in JetBrains IntelliJ IDEA
A critical vulnerability (CVE-2026-59792) with a CVSS score of 9.6 was discovered in JetBrains IntelliJ IDEA, allowing for code execution via path traversal in project workspace ID handling. Users of IntelliJ IDEA versions before 2026.1.4 and 2026.2 are affected. Immediate action is required to update to a patched version.