7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]

7-Zip has released version 26.02 of its popular archiving utility to address a remote code execution (RCE) vulnerability. The flaw, which could allow attackers to execute malicious code, is triggered when users open specially crafted compressed files.
The vulnerability was discovered by Lunbun researcher Landon Peng and is related to 7-Zip's handling of XZ-compressed data. According to an advisory, specially crafted XZ data can lead to a heap-based buffer overflow, potentially enabling arbitrary code execution with the privileges of the user.
While detailed technical specifics from the developer are not yet public, an analysis of the 26.02 source code indicates the patch focuses on how 7-Zip manages available space during XZ decompression. The update introduces checks to prevent the decoder from writing beyond the allocated output buffer, thereby mitigating the heap-based buffer overflow.
Exploitation of this vulnerability requires user interaction, such as visiting a malicious webpage or opening a malicious archive file. Given 7-Zip's widespread use on Windows, such vulnerabilities are considered attractive targets for threat actors. Phishing campaigns or social engineering tactics could be employed to distribute malicious archives designed to exploit this flaw and install malware on vulnerable systems.
Users should be aware that 7-Zip does not feature an automatic update mechanism. Consequently, the security fix will not be applied automatically, and users must manually download and install version 26.02 from the official 7-zip.org website.
This is not the first time 7-Zip has faced security challenges. In early 2025, a 7-Zip vulnerability that allowed malware to bypass Windows' Mark of the Web (MotW) security feature was reportedly exploited as a zero-day by Russian hackers. Later that same year, a different Russian hacking group exploited a WinRAR vulnerability, tracked as CVE-2025-8088, through phishing attacks to deploy RomCom malware.
Currently, there are no confirmed reports of active exploitation of this newly disclosed 7-Zip vulnerability. However, users are strongly advised to update to version 26.02 promptly to reduce their risk of future attacks.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]