SEPM is not impacted.
- CVE-2026-14266 is a HIGH-severity (CVSS 7.0) local vulnerability in 7-zip (versions before 26.02) that requires high attack complexity and user interaction to trigger, an attacker must induce a local user to open a specially crafted archive, potentially leading to full compromise of confidentiality, integrity, and availability.
- SEPM does not bundle, link against, or invoke 7-zip in any capacity. The only reference to 7-zip in the product is inside a SEHOP monitoring rule that lists 7-zip as a third-party process for SEPM to protect on managed endpoints, not a component SEPM uses.
This vulnerability is not applicable to SEP client, as it's not bundled with the product.