A critical vulnerability in 7-Zip has been patched, which previously allowed attackers to execute arbitrary code by tricking users into opening specially crafted XZ-compressed archive files. The flaw, discovered by researcher Landon Peng, is a heap-based buffer overflow that can be triggered when a user opens a malicious file, enabling an attacker to run code with the user's privileges. 7-Zip version 26.02 has been released to address this remote code execution vulnerability, fixing the issue in the program's handling of XZ-compressed data. Although technical details about the vulnerability have not been disclosed, the update is crucial for preventing potential attacks1. This vulnerability poses a significant risk to users who handle compressed files, making it essential to update 7-Zip to the latest version to prevent code execution attacks.