Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
ID: 14cc3419-2eba-5681-b583-43d0f8324fb6
STIX ID: report--14cc3419-2eba-5681-b583-43d0f8324fb6
Feed Name: Security Affairs
Threat Score
7-Zip released version 26.02 to fix a heap-based buffer overflow in its XZ decompression that can allow remote code execution when a user opens a malicious archive; researcher Landon Peng reported the flaw and NHS England reported active exploitation (CVE-2025-11001, CVSS 7.0). Users must manually update because 7-Zip does not auto-update, and attackers may weaponize malicious archives via phishing or social-engineering to deliver malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
