7-Zip
Coverage of 7-Zip in the Nexus archive.
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
A new vulnerability in 7-Zip (CVE-2026-14266) allows code execution when processing crafted XZ archives due to a heap-based buffer overflow. Trend Micro's Zero Day Initiative disclosed the flaw on July 15, and a fix was released in 7-Zip 26.02 on June 25.
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 addresses a remote code execution vulnerability that could allow attackers to execute malicious code through specially crafted compressed files. The update resolves a security flaw exploitable by convincing users to open malicious archives.
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers identified a threat actor named Lurking Lizard using fake 7-Zip installers to operate a malicious residential proxy network via over 230 lookalike domains. The campaign, active since at least August 2022, was tracked by DNS threat intelligence firm Infoblox.