{"id":259965,"date":"2026-05-28T07:00:00","date_gmt":"2026-05-28T11:00:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/28\/wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk-2\/"},"modified":"2026-05-31T00:26:05","modified_gmt":"2026-05-31T04:26:05","slug":"wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk-2","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/28\/wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk-2\/","title":{"rendered":"Wide-ranging 7-zip vulnerability with 8.8 CVE rating allows for code execution \u2014 hundreds of millions of machines potentially at risk"},"content":{"rendered":"<p><a href=\"https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk\">Wide-ranging 7-zip vulnerability with 8.8 CVE rating allows for code execution \u2014 hundreds of millions of machines potentially at risk<\/a><\/p>\n<p><a href=\"https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk\">https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-28 07:00:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.tomshardware.com\">www.tomshardware.com<\/a><\/p>\n<p id=\"elk-88e66e79-06a7-4636-9a39-00c31b8a7c11\">There seems to be no end in sight for serious, wide-ranging security vulnerabilities these days. The ever-popular open-source archive-handling utility 7-Zip is now in the spotlight due to an 8.8-rated CVE vulnerability in its archive-opening procedure. If a user simply opens a booby-trapped crafted archive (.7z, .zip, .rar, etc) on a machine with at least 16 GB of RAM, they&#8217;ll be running malicious code. Extracting the archive isn&#8217;t necessary; only opening it is enough. We recommend that everyone immediately update to the latest version, 26.01, published in late April; all previous versions are vulnerable.<\/p>\n<p>This is a particularly &#8220;oh sugar honey ice tea&#8221; moment because of how widespread 7-Zip is in practice. Most people would only think of the Windows graphical application, but every command-line variant is vulnerable across multiple operating systems. 7-Zip doesn&#8217;t have any built-in update mechanisms, relying instead on user-initiated updates or package management systems.<\/p>\n<p id=\"elk-88e66e79-06a7-4636-9a39-00c31b8a7c11-2\">The Windows application being vulnerable is bad enough; however, one needs to add millions of command-line scripts that are indirectly vulnerable, as are CI\/CD workflows. Anything that so much as calls any variant of the &#8220;7z&#8221; binary and opens a poisoned archive, even if just to list the contents, is at risk.<\/p>\n<p><span class=\"inline-flex items-center gap-1.5 text-sm font-article-heading capitalize leading-5 text-white whitespace-nowrap\"><span class=\"jwp-carousel-title-mobile\"\/><span class=\"jwp-carousel-title-desktop\">Latest Videos From<\/span><span class=\"jwp-carousel-brand inline-flex items-center\" aria-hidden=\"true\"><\/span><\/span><img decoding=\"async\" src=\"https:\/\/www.tomshardware.com\/media\/img\/brand_logo.svg\" alt=\"\" class=\"max-h-12 w-auto\" aria-hidden=\"true\"\/><br \/>\n        <span class=\"\n            flex\n            after:content-[''] after:flex-1 after:ml-4 after:my-[0.7rem] after:border-t after:border-solid after:border-t-[#ccc]\n            before:content-[''] before:flex-1 before:mr-4 before:my-[0.7rem] before:border-t before:border-solid before:border-t-[#ccc]\n            font-article-heading pb-0 text-[length:var(--article-river-title--font-size,1em)] uppercase sm:text-[length:var(--article-river-title--font-size,0.875em)] font-bold\n        \"><br \/>\n            You may like<br \/>\n        <\/span><\/p>\n<p>Go deeper with TH Premium: AI and data centers<\/p>\n<p class=\"vanilla-image-block\" style=\"padding-top:56.25%;\">\n<p><img decoding=\"async\" alt=\"Microsoft data center in Mount Pleasant, Wisconsin\" srcset=\"https:\/\/cdn.mos.cms.futurecdn.net\/Vh4nY3pMCcmra2ymXah9S7-1200-80.jpg 1200w, https:\/\/cdn.mos.cms.futurecdn.net\/Vh4nY3pMCcmra2ymXah9S7-1024-80.jpg 1024w, https:\/\/cdn.mos.cms.futurecdn.net\/Vh4nY3pMCcmra2ymXah9S7-970-80.jpg 970w, https:\/\/cdn.mos.cms.futurecdn.net\/Vh4nY3pMCcmra2ymXah9S7-650-80.jpg 650w, https:\/\/cdn.mos.cms.futurecdn.net\/Vh4nY3pMCcmra2ymXah9S7-480-80.jpg 480w, https:\/\/cdn.mos.cms.futurecdn.net\/Vh4nY3pMCcmra2ymXah9S7-320-80.jpg 320w\" sizes=\"(min-width: 1000px) 970px, calc(100vw - 40px)\" loading=\"lazy\" data-new-v2-image=\"true\" src=\"https:\/\/cdn.mos.cms.futurecdn.net\/Vh4nY3pMCcmra2ymXah9S7.jpg\" data-pin-media=\"https:\/\/cdn.mos.cms.futurecdn.net\/Vh4nY3pMCcmra2ymXah9S7.jpg\" class=\"rounded-[var(--image--border-radius,0)] pinterest-pin-exclude\"\/>\n<\/p>\n<p><span class=\"credit\" itemprop=\"copyrightHolder\">(Image credit: Microsoft)<\/span><\/p>\n<p id=\"elk-d47bab79-a84f-4b9a-a7e8-059c096adf86\">Adding fuel to the fire, a good number of Linux distributions come with long-outdated &#8220;p7zip&#8221; ports of the utility. Heck, just think of a server that automatically lists archive contents for some reason, and it&#8217;s almost certainly vulnerable. Sourceforge lists some 400 million 7-Zip downloads, while Chocolatey has 24.5 million, so adding to that copious amounts of Linux servers and VMs, we could be discussing hundreds of millions of vulnerable machines.<\/p>\n<p>But wait, there&#8217;s more. The open nature of 7z means that its base libraries are included among&#8230;<\/p>\n<p><a href=\"https:\/\/www.tomshardware.com\/tech-industry\/cyber-security\/wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wide-ranging 7-zip vulnerability with 8.8 CVE rating allows for code execution \u2014 hundreds of millions&#8230;<\/p>\n","protected":false},"author":1,"featured_media":259966,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cdn.mos.cms.futurecdn.net\/ucUhNfGZdnCABW3iy4K22E-2121-80.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[20,90,57,27],"class_list":["post-259965","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-artificial-intelligence","tag-cve","tag-security","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/259965"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=259965"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/259965\/revisions"}],"predecessor-version":[{"id":259968,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/259965\/revisions\/259968"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/259966"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=259965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=259965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=259965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}