securityaffairs.com 7/20/2026, 11:41:03 AM · external

7zip XZ file flaw lets hackers run code via malicious archive

7zip XZ file flaw lets hackers run code via malicious archive

A critical vulnerability in 7-Zip, affecting its handling of XZ-compressed files, has been discovered, allowing for potential remote code execution if a user opens a malicious archive. This flaw, identified by researcher Landon Peng, exploits a heap-based buffer overflow. Users are encouraged to update to version 26.02, as the software does not support automatic updates. The exploit requires user interaction, such as opening a crafted file. Previous vulnerabilities in 7-Zip have seen active exploitation, highlighting the risk associated with popular software.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline