LIVE · cybersecurity feed
Live wire
vulnerability

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]

zeroday.news · 14d ago

7-Zip has released version 26.02 of its popular archiving utility to address a remote code execution (RCE) vulnerability. The flaw, which could allow attackers to execute malicious code, is triggered when users open specially crafted compressed files.

The vulnerability was discovered by Lunbun researcher Landon Peng and is related to 7-Zip's handling of XZ-compressed data. According to an advisory, specially crafted XZ data can lead to a heap-based buffer overflow, potentially enabling arbitrary code execution with the privileges of the user.

While detailed technical specifics from the developer are not yet public, an analysis of the 26.02 source code indicates the patch focuses on how 7-Zip manages available space during XZ decompression. The update introduces checks to prevent the decoder from writing beyond the allocated output buffer, thereby mitigating the heap-based buffer overflow.

Exploitation of this vulnerability requires user interaction, such as visiting a malicious webpage or opening a malicious archive file. Given 7-Zip's widespread use on Windows, such vulnerabilities are considered attractive targets for threat actors. Phishing campaigns or social engineering tactics could be employed to distribute malicious archives designed to exploit this flaw and install malware on vulnerable systems.

Users should be aware that 7-Zip does not feature an automatic update mechanism. Consequently, the security fix will not be applied automatically, and users must manually download and install version 26.02 from the official 7-zip.org website.

This is not the first time 7-Zip has faced security challenges. In early 2025, a 7-Zip vulnerability that allowed malware to bypass Windows' Mark of the Web (MotW) security feature was reportedly exploited as a zero-day by Russian hackers. Later that same year, a different Russian hacking group exploited a WinRAR vulnerability, tracked as CVE-2025-8088, through phishing attacks to deploy RomCom malware.

Currently, there are no confirmed reports of active exploitation of this newly disclosed 7-Zip vulnerability. However, users are strongly advised to update to version 26.02 promptly to reduce their risk of future attacks.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.