CVE-2026-2037Disclosure(gfi / archiver)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the configuration of the MArc.Core.Remoting.exe process, which listens on port 8017. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-27935.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archiver

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-17); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
archiver

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-17: 1Mentions · 2026-02-20: 1PoC Mentioned / Linked · 2026-02-17: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-20: 102-1702-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-074|CVE-2026-2037] GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVSS 8.8) https://www.zerodayinitiative.com/advisories/ZDI-26-074/

    Post summary

    The ZeroDay Initiative has announced a remote code execution vulnerability (CVE‑2026‑2037) in GFI Archiver's MArc.Core deserialization component with a CVSS score of 8.8, and the advisory likely contains PoC details, but no exploit or patch information is provided in the excerpt.

    01050517
    5.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2037 GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af… https://www.cve.org/CVERecord?id=CVE-2026-2037

    Post summary

    A new CVE (2026-2037) affecting GFI Archiver’s MArc.Core component has been disclosed, involving deserialization of untrusted data that could enable remote code execution. No proof of concept, exploit, or patch information is provided.

    0000083
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgfiarchiver15.10--

Explore more