Menu

#2692 7-Zip Vulnerabilities

open
None
7
2026-07-31
2026-07-30
No

Hi, we do find some 7-zip vulnerabilities in our server after Nessus scanning. May I know how to remediate these issues?
7-Zip < 26.01 NTFS Heap Buffer Overflow (GHSL-2026-140)
7-Zip >= 9.21 < 26.01 UEFI Multiple Vulnerabilities (GHSL-2026-115_GHSL-2026-122)
7-Zip >= 9.34 < 26.01 WIM / Ar SYMDEF OOB Read (GHSL-2026-115_GHSL-2026-122)

Discussion

  • Sam Tansy

    Sam Tansy - 2026-07-30

    I think it's been fixed.
    At least the first one. I guess, the rest too.

     
    • Arav

      Arav - 2026-07-31

      not fixed.. 7-Zip 26.02, is already the newest version vulnerability scanners separately flags CVE-2026-58052 in 7-Zip 26.02

       
  • Farahin Fauze

    Farahin Fauze - 2026-07-30

    means, by upgrading to version 26.02 can fix this error?

     
    • estomagado

      estomagado - 2026-07-30

      No, it won't.

      I can confirm that both Qualys and Tenable flag 26.02 as vulnerable. This is a different vulnerability, not the one that was fixed with 26.02.

       
      • Farahin Fauze

        Farahin Fauze - 2026-07-31

        can you tell me how to remediate this issues?

         
  • Arav

    Arav - 2026-07-31

    CVE-2026-58052 exists on 7-Zip (ver. 26.02.00.0) -"Action1’s vulnerability scanner separately flags CVE-2026-58052 because that vulnerability affects 7-Zip through version 26.02. There is currently no newer 7-Zip release in Action1’s catalogue to deploy."

    CVE-2026-58052 is a medium-severity security flaw in 7-Zip for Windows through version 26.02 that fails to preserve the Mark-of-the-Web (MotW). It lets attackers bypass Windows SmartScreen warnings and spoof file contents using crafted RAR5 archives.

     

    Last edit: Arav 2026-07-31
    • Farahin Fauze

      Farahin Fauze - 2026-07-31

      thank you for your explaination

       

Log in to post a comment.