7-Zip version 26.02 has been released to address a critical remote code execution vulnerability. This vulnerability allows attackers to execute malicious code if a user opens a specially crafted compressed file.
The flaw, disclosed by Lunabun researcher Landon Peng, pertains to 7-Zip’s handling of XZ compressed data.
According to the Zero Day Initiative, specially crafted XZ data can lead to a heap-based buffer overflow, potentially allowing arbitrary code execution by the attacker on the user’s system.
While technical details regarding this vulnerability have not been released, updates in the 26.02 source code suggest that it relates to how 7-Zip tracks available space during the extraction of XZ data.
This patch implements checks to prevent the decoder from writing beyond the available space in the output buffer, reducing the risk of heap-based buffer overflows.
Notably, exploitation of this vulnerability necessitates user interaction, such as opening a malicious archive file or visiting a harmful webpage.
No Automatic Update Feature
7-Zip currently lacks an automatic update feature, meaning users will not receive security fixes automatically. To ensure you have the latest security enhancements, you must manually download the latest version from the official 7-Zip website.
As one of the most popular archiving utilities for Windows, security flaws affecting 7-Zip make it an appealing target for cybercriminals.
Phishing and social engineering tactics can be leveraged to distribute malicious archives capable of exploiting these vulnerabilities to install malware on susceptible systems.
This concern is grounded in reality; there have been instances where vulnerabilities in archiving software, including 7-Zip, have been actively exploited.
In early 2025, Russian hackers managed to exploit a zero-day vulnerability in 7-Zip, enabling malware to circumvent Windows’ Mark of the Web (MotW) security feature.
Later in the year, hackers employed a phishing attack against WinRAR, exploiting CVE-2025-8088 to install RomCom malware.
Currently, there are no reports indicating active exploitation of the recently disclosed 7-Zip vulnerability. However, we highly recommend updating to version 26.02 promptly to mitigate the risk of potential attacks.
Research shows that 54% of successful attacks go undocumented, with warnings issued for only 14%. The remainder flows invisibly through the system.
Picus’ whitepaper details how to test your SIEM and EDR rules through breach and attack simulations to ensure threats remain detected.
Source: www.bleepingcomputer.com




