Security fixes ship only in new 7-Zip releases; 26.02 and 26.03 fixed CVE-listed vulnerabilities
Catalog row in Vendor License Rules · Cited
- Kind
- Lifecycle
- Statement
- HISTORY of the 7-Zip (26.03 dated 2026-09-03; as published on 2026-09-27): release notes list fixed vulnerabilities by CVE, for example CVE-2026-14266 (XZ decompression heap-based buffer overflow, fixed in 26.02 of 2026-06-25) and CVE-2026-58052 (Mark-of-the-Web not preserved, fixed in 26.03 of 2026-09-03). The project publishes no end-of-life dates or long-term support branches; fixes are delivered as new versions.
- Applies when
- Tracking installed versions against the current release.
- Applies to
- 7-Zip for Windows, Linux and macOS.
- Related programs