logo

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

ID: a52083cd-526f-56dd-baaa-f1c65557f42c

STIX ID: report--a52083cd-526f-56dd-baaa-f1c65557f42c

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

7-Zip released version 26.02 to fix a heap-based buffer overflow in its XZ decompression that could enable arbitrary code execution when a user opens specially crafted compressed files; the patch adds bounds checks to prevent writes beyond available output buffer space. Exploitation requires user interaction (e.g., opening a malicious archive or visiting a page) and there are no reports of active exploitation, so users must update manually because 7-Zip lacks automatic updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.