7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researcher Landon Peng, can be triggered through a specially crafted archive. If a user opens the malicious file, an attacker could exploit a heap-based buffer overflow to execute arbitrary code with the user’s privileges.
The developer has not released technical details about the vulnerability, but the version 26.02 code changes suggest the issue involved improper handling of available buffer space during XZ decompression.
Exploitation requires user interaction, such as opening a malicious archive or visiting a harmful page. 7-Zip does not provide automatic updates, so users must install the latest version manually.
Users should manually update to the latest version.
7-Zip vulnerabilities are privileged targets because the software popularity. Attackers could exploit the flaw by sending malicious archives through phishing or social engineering campaigns to install malware.
In November 2025, NHS England reported active exploitation of a remote code execution vulnerability, tracked as CVE-2025-11001 (CVSS score of 7.0).
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, 7Zip)