7-Zip Fixes Critical XZ Vulnerability
A plain archive file can easily turn into a bad hacking tool. Luckily, the maker of 7-Zip just launched version 26.02 to fix a huge flaw in XZ file tasks. During a real attack, a hacker could run bad code using the victim’s account rights.
Memory Buffer Overflow Risks
Landon Pan, a bright security guard from Lunbun, first found this pressing issue. According to a formal report on ZDI-26-444, crafted XZ data caused a massive memory buffer overflow. To launch this strike, crooks just needed to trick the victim into opening a rigged archive. Also, visiting a hacked webpage that loads the flawed file could spark the trap.
Right now, the 7-Zip maker has not shared a deep tech review of this specific flaw. Yet, checking the core code changes in version 26.02 shows clear hints. The bug clearly grew from wrongly sizing the free space inside the output buffer during XZ data reads. As a result, the fixed tool now strictly checks the leftover memory size. Thus, it fully stops any rogue data writing outside the safe memory zone.
Manual Update Required
The lack of an auto update feature in 7-Zip makes a very risky setup. This famous app will not install the vital patch on its own. Also, it does not promise that users will even get a warning about the threat. So, users must go download the new version straight from the main 7-zip.org site and install it over their old setup.
Phishing Campaigns Target Archivers
As expected, hackers often abuse flaws in top zip tools during email scams. Attackers often send bad archives hidden as standard invoices, resumes, or normal work files. After this trick, they quietly load harmful malware onto the victims’ computers.
Similar risky events have surely happened before. Early in 2025, an unknown 7-Zip flaw helped hackers bypass the vital Windows Mark of the Web safety tag. This key tag normally warns users about the hidden risks of online files. Later, bad actors actively used a known flaw in WinRAR to spread the RomCom virus via fake scam emails.
Immediate Action Advised
Right now, security groups have not seen any active attacks using this new 7-Zip bug. Still, experts strongly advise that all users move to version 26.02 right away. This advice stands super important if you often use the app to open files from emails, chat apps, or other outside sources.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.