Users are being urged to update to 7-Zip version 26.02 after a newly disclosed security vulnerability was found that could allow attackers to execute malicious code on Windows systems.
The flaw, discovered by Lunbun researcher Landon Peng, was fixed in the latest release on June 25.
The vulnerability affects how 7-Zip processes XZ-compressed data. According to the Zero Day Initiative, a specially crafted XZ archive can trigger a heap-based buffer overflow, potentially allowing arbitrary code to run with the same privileges as the user who opens the file.
Although the 7-Zip developer has not released detailed technical information, changes in the updated source code indicate the issue was caused by insufficient checks while tracking available space during XZ decompression. The fix introduces additional validation to prevent data from being written beyond the allocated output buffer, eliminating the buffer overflow condition.
Exploiting the flaw requires user interaction, meaning victims would need to open a malicious archive or be tricked into downloading and accessing a specially crafted compressed file. Attackers could distribute these files through phishing emails or other social engineering techniques to deliver malware.
Unlike many modern applications, 7-Zip does not include an automatic update feature. Users must manually download and install version 26.02 from the official 7-Zip website to receive the security fix.
Archive utility vulnerabilities have been abused by cybercriminals before. In early 2025, attackers exploited a separate 7-Zip flaw that bypassed Windows’ Mark of the Web protection, while later that year another hacking group used a WinRAR vulnerability in phishing attacks to deploy RomCom malware.
There are currently no reports of this newly patched vulnerability being actively exploited in the wild. Even so, users are strongly encouraged to install 7-Zip 26.02 as soon as possible to protect their systems from potential future attacks.





