A critical vulnerability in 7-Zip has been patched, which previously allowed attackers to execute arbitrary code by tricking users into opening specially crafted XZ-compressed archive files. The flaw, discovered by researcher Landon Peng, is a heap-based buffer overflow that can be triggered when a user opens a malicious file, enabling an attacker to run code with the user's privileges. 7-Zip version 26.02 has been released to address this remote code execution vulnerability, fixing the issue in the program's handling of XZ-compressed data. Although technical details about the vulnerability have not been disclosed, the update is crucial for preventing potential attacks1. This vulnerability poses a significant risk to users who handle compressed files, making it essential to update 7-Zip to the latest version to prevent code execution attacks.
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
⚠️ Critical Alert
Why This Matters
7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files.
References
- SecurityAffairs. (2026, July 20). Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! *SecurityAffairs*. https://securityaffairs.com/195688/security/critical-7-zip-flaw-allows-code-execution-by-opening-crafted-xz-compressed-files-update-it-now.html
Original Source
SecurityAffairs
Read original →