CVE Tools

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

BleepingComputerBy Lawrence Abrams

Patch7-Zip

Our summary

7-Zip has issued version 26.02 to resolve a high-risk remote code execution (RCE) vulnerability that could let attackers run malicious code through specially crafted XZ-compressed files. The flaw, identified by researcher Landon Peng and detailed in ZDI-26-444, stems from improper handling of available space during decompression, leading to potential heap-based buffer overflows. While no active exploitation has been reported yet, the lack of an automatic update mechanism means users must manually upgrade to mitigate risks. Given 7-Zip’s widespread use, unpatched systems remain exposed to targeted attacks involving malicious archives.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store