7-Zip Vulnerabilities
A free file archiver for extremely high compression
Brought to you by:
ipavlov
Hi, we do find some 7-zip vulnerabilities in our server after Nessus scanning. May I know how to remediate these issues?
7-Zip < 26.01 NTFS Heap Buffer Overflow (GHSL-2026-140)
7-Zip >= 9.21 < 26.01 UEFI Multiple Vulnerabilities (GHSL-2026-115_GHSL-2026-122)
7-Zip >= 9.34 < 26.01 WIM / Ar SYMDEF OOB Read (GHSL-2026-115_GHSL-2026-122)
I think it's been fixed.
At least the first one. I guess, the rest too.
not fixed.. 7-Zip 26.02, is already the newest version vulnerability scanners separately flags CVE-2026-58052 in 7-Zip 26.02
means, by upgrading to version 26.02 can fix this error?
No, it won't.
I can confirm that both Qualys and Tenable flag 26.02 as vulnerable. This is a different vulnerability, not the one that was fixed with 26.02.
can you tell me how to remediate this issues?
CVE-2026-58052 exists on 7-Zip (ver. 26.02.00.0) -"Action1’s vulnerability scanner separately flags CVE-2026-58052 because that vulnerability affects 7-Zip through version 26.02. There is currently no newer 7-Zip release in Action1’s catalogue to deploy."
CVE-2026-58052 is a medium-severity security flaw in 7-Zip for Windows through version 26.02 that fails to preserve the Mark-of-the-Web (MotW). It lets attackers bypass Windows SmartScreen warnings and spoof file contents using crafted RAR5 archives.
Last edit: Arav 2026-07-31
thank you for your explaination