7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip’s processing of XZ-compressed data.
According to an advisory from the Zero Day Initiative published this week, a specially crafted XZ data can trigger a heap-based buffer overflow, potentially allowing attackers to execute arbitrary code as the user.
While the developer has not published technical details about the flaw, the changes in the 26.02 source code suggest it is related to how 7-Zip tracks available space while decompressing XZ data.
The patch adds checks to ensure the decoder cannot write beyond the remaining available space in an output buffer, helping prevent a heap-based buffer overflow.
The advisory states that exploitation requires user interaction, such as visiting a malicious page or opening a malicious archive file.
As 7-Zip does not include an automatic update feature, users will not receive the security fix automatically. Instead, they must install it manually by downloading the latest version from the program’s official site, 7-zip.org.
Because 7-Zip is one of the most widely used archive utilities on Windows, security flaws impacting its archive features are an attractive target to threat actors.
A phishing campaign or social engineering attack could be used to distribute a malicious archive that exploits the flaw to install malware on vulnerable systems.
This is not far-fetched, as archive vulnerabilities, including those in 7-Zip, have been exploited in past attacks.
In early 2025, a 7-Zip vulnerability that allowed malware to bypass Windows’ Mark of the Web (MotW) security feature was exploited by Russian hackers as a zero-day.
Later that same year, a Russian hacking group exploited a WinRAR vulnerability tracked as CVE-2025-8088 via phishing attacks to install the RomCom malware.
There are currently no reports that attackers are actively exploiting this newly disclosed 7-Zip vulnerability.
However, users are advised to update to version 26.02 as soon as possible to reduce the risk of future attacks.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
WordPress Core “wp2shell” RCE flaws get public exploits, patch now
Critical Langflow RCE flaw exploited to hack AI app servers
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
FFmpeg fixes PixelSmash flaw in widely used video decoder
Microsoft fixes AutoGen Studio flaw that enabled code execution
>As 7-Zip does not include an automatic update feature, users will not receive the security fix automatically. Instead, they must install it manually by downloading the latest version from the program’s official site, 7-zip.org. Or via winget/unigetui. The latter one in particular has become extremely mature at this point and is a huge time-saver.
26.02 was released June 25th. The title of the article suggests that it was a more recent release, so adding the release date next to the version number might be a good idea.
News of the vulnerability was released on July 15th, which is why it was reported this week. I added the date of the version release to the lede.
Ernst & Young discloses data breach after support system hack
New Windows LegacyHive zero-day gives hackers admin privileges
CISA urges immediate action on actively exploited Fortinet flaws
AI is a data-breach time bomb: Read the new report
See how Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Read the case study.
Pentest your web apps on-demand. Find what humans miss. Scope and launch a pentest in minutes.
Privacy by policy or privacy by architecture? See how age checks work when the face never leaves the device.
AI broke vulnerability management. Get the guide CISOs use to shift budget to BAS.
Do you have what it takes to challenge DARKROOM? Signup for an exclusive DEFCON CTF!
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



