Impact of 7zip vulnerability CVE-2026-14266 on Endpoint Protection
search cancel

Impact of 7zip vulnerability CVE-2026-14266 on Endpoint Protection

book

Article ID: 450344

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

You want to know if Symantec Endpoint Protection Manager (SEPM) / Symantec Endpoint Protection (SEP) client is impacted by 7zip releated vulnerability CVE-2026-14266. 

Resolution

SEPM is not impacted. 

  • CVE-2026-14266 is a HIGH-severity (CVSS 7.0) local vulnerability in 7-zip (versions before 26.02) that requires high attack complexity and user interaction to trigger, an attacker must induce a local user to open a specially crafted archive, potentially leading to full compromise of confidentiality, integrity, and availability.
  • SEPM does not bundle, link against, or invoke 7-zip in any capacity. The only reference to 7-zip in the product is inside a SEHOP monitoring rule that lists 7-zip as a third-party process for SEPM to protect on managed endpoints, not a component SEPM uses.

This vulnerability is not applicable to SEP client, as it's not bundled with the product.