7-Zip 26.03 on Windows: update the right copy and check archives safely

As of 1 October 2026. The 3 September 2026 release of 7-Zip 26.03 is a reason to check the extractor you actually use. This guide is for Windows users and small IT teams handling downloaded archives. A successful installation is only part of the job: shortcuts and workflows must use the updated copy afterwards.

Why this update matters

The developer lists CVE-2026-58052 as fixed: extraction of a crafted archive did not preserve Mark-of-the-Web. Updating is therefore worthwhile, but does not make unknown files trustworthy. The release note alone does not establish an active attack campaign or prove that a particular computer was compromised.

7-Zip — 26.03 / 2026-09-03

Preparation and package choice

You need a supported Windows system, permission to install software and a harmless archive of your own for testing. Use the approved IT deployment route on managed devices. Preserve important original archives and allow enough space for extracted data. The download page offers x64, x86 and ARM64; check System type in Settings > System > About. ARM64 is not x64. The developer prefers the EXE installer to MSI; do not independently replace an existing managed MSI deployment. Linux/macOS console packages are not substitutes for the Windows installer.

7-Zip — Download

Update step by step

  1. Record the starting point: open the 7-Zip File Manager you normally use, note its version in the Help/About dialog and check the program path in the shortcut properties. For scripts, also record the executable path actually called.
  2. Choose the download deliberately: open the official download page linked below and select the correct Windows architecture for 26.03. Avoid download advertisements and similarly named websites. Check any newer release against its own release notes before installing it.
  3. Finish running archive jobs and close 7-Zip. Run the intended installer, using administrator rights only for the installation that requires them. Stop at an unexpected security warning and clarify the source or IT approval; do not disable protection.
  4. Reopen 7-Zip and check both version and path. If the old version remains, investigate the shortcut, an additional installation or an embedded copy first. One installation does not demonstrably update every portable copy or third-party application.
  5. Select a self-created, nonconfidential test archive and use Test to check for archive errors. Then use Extract to unpack into a new empty folder. Do not overwrite production files or launch unknown executables.
  6. Compare the number, names and contents of the known test files with the originals. Also check the usual Explorer action and, where applicable, an approved script workflow using test data; record the version, date and result.

Check the result

The relevant installation is checked when the path actually used reports 26.03 or a separately reviewed newer version and the known test case completes without errors. Passing an archive test neither detects all malware nor proves the vulnerability fix. We provide no crafted archives and claim no hands-on exploit, installation or performance test.

If something goes wrong

For CRC/data errors, preserve the original and check download completeness, all parts of a split archive and, where needed, the correct password. Do not send passwords to the editorial team. If only one external archive fails, ask its sender for another copy or format details. For insufficient space, check the destination; direct extraction avoids the extra Explorer copy stage used when dragging out of 7-Zip. If the workflow breaks after updating, pause it and give the findings to IT instead of automatically installing an older version.

7-Zip — FAQ

Scope and sources

This is a source-based guide with an editorially proposed verification routine, not a product test. It contains no affiliate links, purchase recommendation or measured search-trend claim. The developer links support the release and package selection; our checks do not guarantee malware-free files.