There is a good chance your business uses 7-Zip and nobody has thought about it in months. It is one of those tools that gets installed, does its job quietly, and never gets updated unless someone specifically makes it happen.

That needs to change today.
A newly disclosed security vulnerability in 7-Zip, one of the most widely used file compression tools in the world, could allow an attacker to run malicious code on your computer simply by getting you to open a specially crafted archive file. A patch is already available. The only question is whether your machines have it.
What the Vulnerability Is
The flaw, identified as CVE-2026-14266, was disclosed publicly on July 15th by Trend Micro's Zero Day Initiative and rated High severity. It affects the way 7-Zip handles a specific type of compressed file called an XZ archive. Due to a flaw in the way 7-Zip processes the data inside these files, an attacker can craft a malicious archive that causes 7-Zip to write data outside the boundaries of its own memory — a condition known as a buffer overflow. When that happens, the attacker's code runs on the machine.
In plain terms: if someone sends you a booby-trapped compressed file and you open it with an unpatched version of 7-Zip, the attacker can execute code on your computer.
The vulnerability has existed in 7-Zip's code since at least 2021, though researchers have not confirmed exactly which older versions are exploitable. As of today there are no confirmed cases of this being actively exploited in the wild, but that window can close quickly once details become public.
How an Attack Would Work
The attacker does not need to be on your network or have any access to your systems. They simply need to deliver a malicious file to someone on your team and get that person to open it. That file could arrive as an email attachment, a download link, a file shared through a messaging platform, or even a document passed along through a vendor or partner.
The moment the file is opened in an unpatched version of 7-Zip, the attack executes. The code runs with the same permissions as the person who opened the file, which means on most business machines it would have access to files, applications, and potentially network resources that employee can reach.
The Good News
A fix is already available. 7-Zip version 26.02 was released on June 25th and patches this vulnerability along with several other security flaws discovered earlier this year. Anyone who updated in late June was already protected before the vulnerability details were even made public. One update covers everything.
The challenge is that 7-Zip does not update itself automatically. It has to be updated manually, or pushed out through an IT management system. That means every machine in your environment that runs 7-Zip needs to be checked and updated individually unless your IT team manages that process centrally.
Where Businesses Are Most Exposed
Unmanaged or overlooked devices are the highest risk. Laptops that employees use from home, older workstations that rarely get attention, and machines running software installed years ago and never touched since are exactly where unpatched vulnerabilities live the longest.
Any employee who regularly receives and opens compressed files from outside the organization is a potential entry point. That includes finance teams opening invoices and statements, operations staff receiving files from vendors and suppliers, and anyone who downloads files shared through email or collaboration platforms.
Third-party software that bundles 7-Zip is also worth noting. Some applications ship their own internal copy of 7-Zip's code. Those copies need their own vendor updates and will not be fixed simply by updating the standalone 7-Zip application.
What Your Team Should Do Right Now
Check every machine that has 7-Zip installed and confirm it is running version 26.02 or later. You can check the version by opening 7-Zip File Manager and clicking Help, then About. If the version shown is anything older than 26.02, update it immediately from the official 7-Zip website at 7-zip.org.
If your business manages devices through an IT management platform, push this update across all endpoints now rather than waiting for employees to do it themselves.
Remind your team to be cautious about opening compressed archive files received from outside the organization, especially unexpected ones. A file with an unfamiliar extension like .xz, .7z, .zip, or similar formats should be treated with the same caution as any other attachment from an unknown source.
If your business uses any software that bundles or depends on 7-Zip internally, check with that vendor to confirm whether their product is affected and whether an update is available.
The Bottom Line
The patch exists. It has existed since June 25th. The only machines at risk right now are the ones that have not been updated yet. 7-Zip does not update on its own, which means this is one of those vulnerabilities that will quietly linger on unmanaged machines long after the fix is available. Five minutes of attention today closes the door on an attack that could otherwise give an outsider access to your systems.
