A regular archive can turn into a tool to hack a computer. The developer 7-Zip has released a version of 26.02 that closes the vulnerability in XZ file processing. With a successful attack, the attacker could run malicious code with user rights.
The problem, which received the identifier CVE-20266, was discovered by researcher Landon Pan of the company Lungun. According to the Zero Day Initiative, specially prepared XZ data caused buffer overflow in dynamic memory. To attack, the victim was required to convince you to open the malicious archive or visit a page that handles such a file.
The developer 7-Zip has not yet published a detailed technical description of the vulnerability. Changes in the source code of version 26.02 indicate that the error was associated with the calculation of the free space in the output buffer during the XZ data unpacking. The updated decoder checks the remaining amount of memory and does not allow you to record data outside the selected area.
A particular danger is the absence of automatic update in 7-Zip. The program will not install the correction on its own and does not guarantee that the user receives a warning. The new version needs to be downloaded manually from the official 7-zip.org website and install on top of the old one.
Vulnerabilities in popular archivers are regularly used in phishing attacks. Criminals send archives under the guise of documents, accounts, resumes or service files, after which they install malware on the victims’ computers.
Such cases have already occurred. At the beginning of 2025, the unknown at that time vulnerability 7-Zip allowed to bypass the security label of Windows Mark of the Web, which warns about the dangers of files from the Internet. Later, the attackers used the vulnerability CVE-2025-8088 to WinRAR to spread the RomCom malware through phishing emails.
Signs of exploitation of a new 7-Zip vulnerability have not yet been found. Users are advised to go to version 26.02 as soon as possible, especially if the archiver is used to open files from email, messengers and other external sources.
The problem, which received the identifier CVE-20266, was discovered by researcher Landon Pan of the company Lungun. According to the Zero Day Initiative, specially prepared XZ data caused buffer overflow in dynamic memory. To attack, the victim was required to convince you to open the malicious archive or visit a page that handles such a file.
The developer 7-Zip has not yet published a detailed technical description of the vulnerability. Changes in the source code of version 26.02 indicate that the error was associated with the calculation of the free space in the output buffer during the XZ data unpacking. The updated decoder checks the remaining amount of memory and does not allow you to record data outside the selected area.
A particular danger is the absence of automatic update in 7-Zip. The program will not install the correction on its own and does not guarantee that the user receives a warning. The new version needs to be downloaded manually from the official 7-zip.org website and install on top of the old one.
Vulnerabilities in popular archivers are regularly used in phishing attacks. Criminals send archives under the guise of documents, accounts, resumes or service files, after which they install malware on the victims’ computers.
Such cases have already occurred. At the beginning of 2025, the unknown at that time vulnerability 7-Zip allowed to bypass the security label of Windows Mark of the Web, which warns about the dangers of files from the Internet. Later, the attackers used the vulnerability CVE-2025-8088 to WinRAR to spread the RomCom malware through phishing emails.
Signs of exploitation of a new 7-Zip vulnerability have not yet been found. Users are advised to go to version 26.02 as soon as possible, especially if the archiver is used to open files from email, messengers and other external sources.