Switch language한국어
Back to the list

Wide-ranging 7-Zip vulnerability with 8.8 CVE rating allows for code execution — hundreds of millions of machines potentially at risk

TL;DR AI

Key summary

2 min read
  1. 7-Zip has an 8.8-rated vulnerability in its archive-opening code that can lead to code execution when a crafted file is opened.

  2. The flaw affects multiple archive types and platforms, including the main app, command-line tools, bundled libraries, and older Linux ports like p7zip.

  3. Attackers do not need the user to extract the file; simply opening a malicious archive may be enough to trigger the issue.

  4. Users and admins are advised to upgrade to 7-Zip 26.01 as soon as possible.

Read the original