7-Zip fixes Remote Code Execution (RCE) flaw exploitable with malicious archives

7-Zip fixes Remote Code Execution (RCE) flaw exploitable with malicious archives

Information:

  7-Zip is a popular open-source file compression and decompression utility that lets you compress files into smaller archives and extract files from existing ones. 7-Zip supports a wide range of formats for both compression and extraction. It can compress files into the 7z format, which generally offers a higher compression ratio than other formats such as ZIP. It can also extract files from various formats, including 7z, ZIP, GZIP, BZIP2, TAR, and others.

 Incident :

7-Zip version 26.02 was released on June 25, 2026 to fix a remote code execution (RCE) vulnerability found in the processing of XZ-compressed data.

  A specially crafted XZ file can trigger a heap-based buffer overflow during the decompression process, allowing an attacker to execute arbitrary code on the victim's system. Exploitation requires user interaction, such as opening a malicious archive file or visiting a malicious website. Currently, there are no reports of active exploitation.

Solution :

  • Update immediately to 7-Zip 26.02 or later
  • Avoid opening archive files from unknown or untrusted sources
  • Enable email attachment scanning to catch malicious compressed files before delivery
  • Educate employees on the risks of opening unsolicited compressed attachments

The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)

References :

Weekly Interesting CVE

NO.

CVE Name

Published Date

Last Update

Device/Appplication/OS Target

Attack Type

CVSS
Severity Rating

Detail

Solution

Reference

1

CVE-2026-46817

9/7/2026

11/7/2026

Joomla extension Balbooa Forms 2.4.0 or earlier

Unrestricted Upload of File with Dangerous Type

10

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Balbooa fixed it in version 2.4.1, released on 9 July 2026.

https://www.cvedetails.com/cve/CVE-2026-56291/

2

CVE-2026-39808

14/4/2026

17/7/2026

Fortinet FortiSandbox ver. 4.4.0 – 4.4.8

OS Command Injection

9.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands.

Upgrade FortiSandbox to 4.4.9 or later.

https://nvd.nist.gov/vuln/detail/CVE-2026-39808

3

CVE-2026-58644

14/4/2026

17/7/2026

Microsoft SharePoint

Execute code

9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Microsoft SharePoint Server Subscription Edition
Upgrade to 16.0.19725.20384
Microsoft SharePoint Server 2019
Upgrade to 16.0.10417.20153
Microsoft SharePoint Enterprise Server 2016
Upgrade to 16.0.5556.1005

https://www.cvedetails.com/cve/CVE-2026-58644/

 4

CVE-2026-58626

14/7/2026

16/7/2026

Windows Remote Desktop for
Windows 10 (21H2) before 10.0.19044.7548
Windows 10 (22H2) before 10.0.19045.7548
Windows 11 (24H2) before 10.0.26100.8875
Windows 11 (25H2) before 10.0.26100.8875
Windows 11 (26H1) before 10.0.28000.2525
Windows Server 2022 before 10.0.20348.5386
Windows Server 2025 before 10.0.26100.33158
Windows Server 2025 (Server Core) before 10.0.26100.33158

Use After Free

8.8

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

Windows 10 (21H2) upgrade to 10.0.19044.7548
Windows 10 (22H2) upgrade to 10.0.19045.7548
Windows 11 (24H2) upgrade to 10.0.26100.8875
Windows 11 (25H2) upgrade to 10.0.26100.8875
Windows 11 (26H1) upgrade to 10.0.28000.2525
Windows Server 2022 upgrade to 10.0.20348.5386
Windows Server 2025 upgrade to 10.0.26100.33158
Windows Server 2025 (Server Core) upgrade to 10.0.26100.33158

https://nvd.nist.gov/vuln/detail/CVE-2026-58626

5

CVE-2026-58617

14/7/2026

16/7/2026

Microsoft 365 Copilot for iOS before 2.111.4

Access Control

8.1

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network

Upgrade to 2.111.4 or later.

https://nvd.nist.gov/vuln/detail/CVE-2026-58617

Malware News or Campaign IOC/IOA | EN

No

Campaign Name

Detection Date

Attack

Type

 

Description

 

Mitigation/Remediation

1

New Agent Data Injection Attack Can Make AI Agents Perform Dangerous Actions​

20/07/2026​

Agent Data Injection (ADI),​

AI Agent Manipulation,​

Indirect Prompt Injection​

Researchers have discovered a novel attack technique called Agent Data Injection (ADI), which differs from traditional Prompt Injection. Instead of directly instructing the AI ​​via the prompt, attackers manipulate data that the AI ​​perceives as trustworthy, such as tool output or supporting data. This allows the AI ​​to make decisions and act based on this distorted information. In tests, researchers were able to trick AI coding agents across various platforms, including Claude Code, OpenAI Codex, and Gemini CLI, into performing risky actions such as clicking malicious links, executing unsafe code, or launching supply chain attacks. A key takeaway from this research is that AI agents cannot effectively distinguish between trustworthy and manipulated data. Therefore, organizations implementing AI agents should restrict agent access based on the Least Privilege principle and require user authentication before performing actions that could impact the system, thereby mitigating the risk of this type of attack.​

  • Define AI Agent permissions based on the Least Privilege principle, allowing access only to necessary resources.​
  • Protect API Keys, Credentials, and Secrets from unnecessary access by AI Agents.​
  • Regularly update security patches.​

Ref: https://www.theregister.com/cyber-crime/2026/07/07/cai-cloud-worm-gives-competitors-malware-the-boot-then-steals-secrets-and-mines-for-coin/5267856 

31 July 2026

Viewed 54 time

Engine by shopup.com