7-Zip fixes remote code execution flaw in version 26.02

The popular file compression tool's vulnerability affects millions of users who could execute malicious code simply by opening a crafted archive.

Abstract illustration representing file compression and security vulnerability
AI-generated illustration · Sylvaris

Critical flaw in widely used compression tool

7-Zip has released version 26.02 to address a remote code execution vulnerability discovered in the popular open-source file compression utility. The flaw allows attackers to execute arbitrary code on a victim's system when the user opens a specially crafted compressed file.

The vulnerability represents a significant risk given 7-Zip's widespread deployment across Windows systems for handling ZIP, RAR, and other archive formats. Users typically trust compressed files as passive containers, making this attack vector particularly effective.

Immediate update recommended

Security researchers recommend that all 7-Zip users upgrade to version 26.02 immediately. The update process is straightforward and available through the official 7-Zip website.

Organizations should inventory systems where 7-Zip is installed and prioritize patching, particularly on machines that regularly handle files from external or untrusted sources. Until updated, users should exercise caution when opening archive files from unknown senders.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.