mention CVE-2017-14107
diff --git a/NEWS.md b/NEWS.md
index 81a2963..f09fee6 100644
--- a/NEWS.md
+++ b/NEWS.md
@@ -5,6 +5,7 @@
 * Improve file progress callback code
 * Fix zip_fdopen()
 * CVE-2017-12858: Fix double free().
+* CVE-2017-14107: Improve EOCD64 parsing.
 
 1.2.0 [2017-02-19]
 ==================