<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — 7-Zip</title><description>Vulnerabilities in Igor Pavlov&apos;s 7-Zip, the open-source archive utility bundled or installed on tens of millions of Windows endpoints. 7-Zip ships without an auto-update mechanism, so parser bugs — heap overflows in Zstd, XZ, or LZMA decompression, path-traversal in extraction — tend to sit on user machines long after the fix is out. Combined article + CVE feed for the 7-Zip beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2025-0411 — 7-Zip Mark of the Web Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2025-0411/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-0411/</guid><description>7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>7-Zip</category><category>high</category><category>cve</category></item><item><title>7-Zip 26.02 patches XZ heap overflow, no auto-update</title><link>https://0daynews.com/articles/2026-07-18-7-zip-26-02-xz-heap-overflow-rce-zdi-26-444/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-18-7-zip-26-02-xz-heap-overflow-rce-zdi-26-444/</guid><description>7-Zip 26.02 fixes a heap-based buffer overflow in XZ decompression (ZDI-26-444) — RCE if a user opens a crafted archive, and there is no automatic update.</description><pubDate>Sat, 18 Jul 2026 21:00:00 GMT</pubDate><category>7-Zip</category><category>article</category></item></channel></rss>