Security Affairs
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage|Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!|CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers|AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign|Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106|Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION|Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits|OpenSSL Fixes HollowByte Memory Exhaustion Bug|Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network|U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog|Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets|Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage|Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!|CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers|AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign|Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106|Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION|Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits|OpenSSL Fixes HollowByte Memory Exhaustion Bug|Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network|U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog|Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!

7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researcher Landon Peng, can be triggered through a specially crafted archive. If a user opens […]

7-Zip zero-day vulnerability

7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files.

7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researcher Landon Peng, can be triggered through a specially crafted archive. If a user opens the malicious file, an attacker could exploit a heap-based buffer overflow to execute arbitrary code with the user’s privileges.

The developer has not released technical details about the vulnerability, but the version 26.02 code changes suggest the issue involved improper handling of available buffer space during XZ decompression.

Exploitation requires user interaction, such as opening a malicious archive or visiting a harmful page. 7-Zip does not provide automatic updates, so users must install the latest version manually.

Users should manually update to the latest version.

7-Zip vulnerabilities are privileged targets because the software popularity. Attackers could exploit the flaw by sending malicious archives through phishing or social engineering campaigns to install malware.

In November 2025, NHS England reported active exploitation of a remote code execution vulnerability, tracked as CVE-2025-11001 (CVSS score of 7.0).

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, 7Zip)