<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>7Zip on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/7zip/</link><description>Recent content in 7Zip on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 20 Jul 2026 15:55:24 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/7zip/index.xml" rel="self" type="application/rss+xml"/><item><title>7-Zip Carried a Hidden Code Execution Flaw in Its XZ Files for Eight Years</title><link>https://hackingpassion.com/7-zip-xz-heap-overflow/</link><pubDate>Mon, 20 Jul 2026 15:55:24 +0200</pubDate><guid>https://hackingpassion.com/7-zip-xz-heap-overflow/</guid><description>&lt;p>You opened an archive in 7-Zip, and the code that let it take over your machine had been sitting there since 2018. It was quietly patched on June 25. You were not told what it fixed until three weeks later.&lt;/p>
&lt;p>On July 15, the Zero Day Initiative laid out the details in advisory &lt;strong>ZDI-26-444&lt;/strong>, tracked as &lt;strong>CVE-2026-14266&lt;/strong>. It described a flaw in 7-Zip that lets a malicious archive run code the moment you open it. Before that day, the only thing 7-Zip had said about it was a June release that explained nothing.&lt;/p></description></item></channel></rss>