7-Zip fixes Remote Code Execution (RCE) flaw exploitable with malicious archives

Information:
7-Zip is a popular open-source file compression and decompression utility that lets you compress files into smaller archives and extract files from existing ones. 7-Zip supports a wide range of formats for both compression and extraction. It can compress files into the 7z format, which generally offers a higher compression ratio than other formats such as ZIP. It can also extract files from various formats, including 7z, ZIP, GZIP, BZIP2, TAR, and others.
Incident :
7-Zip version 26.02 was released on June 25, 2026 to fix a remote code execution (RCE) vulnerability found in the processing of XZ-compressed data.
A specially crafted XZ file can trigger a heap-based buffer overflow during the decompression process, allowing an attacker to execute arbitrary code on the victim's system. Exploitation requires user interaction, such as opening a malicious archive file or visiting a malicious website. Currently, there are no reports of active exploitation.
Solution :
The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)
References :
Weekly Interesting CVE
| NO. |
CVE Name |
Published Date |
Last Update |
Device/Appplication/OS Target |
Attack Type |
CVSS |
Detail |
Solution |
Reference |
|---|---|---|---|---|---|---|---|---|---|
| 1 |
CVE-2026-46817 |
9/7/2026 |
11/7/2026 |
Joomla extension Balbooa Forms 2.4.0 or earlier |
Unrestricted Upload of File with Dangerous Type |
10 |
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. |
Balbooa fixed it in version 2.4.1, released on 9 July 2026. |
|
| 2 |
CVE-2026-39808 |
14/4/2026 |
17/7/2026 |
Fortinet FortiSandbox ver. 4.4.0 – 4.4.8 |
OS Command Injection |
9.8 |
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands. |
Upgrade FortiSandbox to 4.4.9 or later. |
|
| 3 |
CVE-2026-58644 |
14/4/2026 |
17/7/2026 |
Microsoft SharePoint |
Execute code |
9.8 |
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
Microsoft SharePoint Server Subscription Edition |
|
| 4 |
CVE-2026-58626 |
14/7/2026 |
16/7/2026 |
Windows Remote Desktop for |
Use After Free |
8.8 |
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
Windows 10 (21H2) upgrade to 10.0.19044.7548 |
|
| 5 |
CVE-2026-58617 |
14/7/2026 |
16/7/2026 |
Microsoft 365 Copilot for iOS before 2.111.4 |
Access Control |
8.1 |
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network |
Upgrade to 2.111.4 or later. |
Malware News or Campaign IOC/IOA | EN
|
No |
Campaign Name |
Detection Date |
Attack Type |
Description |
Mitigation/Remediation |
|---|---|---|---|---|---|
| 1 |
New Agent Data Injection Attack Can Make AI Agents Perform Dangerous Actions |
20/07/2026 |
Agent Data Injection (ADI), AI Agent Manipulation, Indirect Prompt Injection |
Researchers have discovered a novel attack technique called Agent Data Injection (ADI), which differs from traditional Prompt Injection. Instead of directly instructing the AI via the prompt, attackers manipulate data that the AI perceives as trustworthy, such as tool output or supporting data. This allows the AI to make decisions and act based on this distorted information. In tests, researchers were able to trick AI coding agents across various platforms, including Claude Code, OpenAI Codex, and Gemini CLI, into performing risky actions such as clicking malicious links, executing unsafe code, or launching supply chain attacks. A key takeaway from this research is that AI agents cannot effectively distinguish between trustworthy and manipulated data. Therefore, organizations implementing AI agents should restrict agent access based on the Least Privilege principle and require user authentication before performing actions that could impact the system, thereby mitigating the risk of this type of attack. |
|
31 July 2026
Viewed 54 time