Overview
- Researcher Landon Peng reported the flaw to 7‑Zip on June 5, 2026 and the project shipped version 26.02 with a fix on June 25, 2026.
- The bug is a heap-based buffer overflow in the MixCoder_Code function of the XZ decoder that miscalculates remaining output buffer space and can cause out-of-bounds writes.
- Trend Micro’s Zero Day Initiative scored the issue CVSS 7.0 and said exploitation requires a victim to open a crafted XZ file delivered by email, download, or a web page.
- As of July 20, 2026 there are no public proof‑of‑concepts or confirmed active exploits, but systems and third-party products that bundle 7‑Zip remain at risk until they receive the patched build.
- Organizations should install 7‑Zip 26.02, verify any shipped copies of the XZ decoder, scan or sandbox XZ attachments at gateways, and train users to avoid opening unknown archives because this bug joins a recent run of 7‑Zip memory-safety flaws.