CVE-2026-58052Active Exploitation(7-zip / 7-zip)

MEDIUMCVSS 4.8 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch 7-zip 7-zip systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with ZoneId=0. A second STM record named '::$DATA' overwrites the extracted file's default data stream, letting an attacker defeat SmartScreen/MotW warnings and spoof file content.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 7-zip

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-06-28); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
7-zip

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-28: 2Mentions · 2026-07-30: 1Mentions · 2026-09-04: 1Mentions · 2026-09-24: 1Active Exploitation · 2026-06-28: 1Patch / Workaround · 2026-09-04: 1Technical Details · 2026-09-04: 106-2807-3009-0409-24
Signal classification4 categories
Active Exploitation
125.0%
Disclosure
125.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-282
Active Exploitation1Disclosure1
2026-07-301
General1
2026-09-041
Patch1
Full discourse5 posts
  • Scooter Software@ScooterSoftware

    We've released Beyond Compare 5.2.6.32774. General polish, stability improvements, and vulnerability fixes. Updated 7-zip to 26.03. Fixes CVE-2026-58052.

    110222768
    2.2K followersView on X
  • エクシードシステム(Y.Sakamoto)@exceedsystem
    General

    Windows環境では7-Zipを長らく愛用してるけど、最新版でも未解決の脆弱性が公開されているな…。 https://nvd.nist.gov/vuln/detail/CVE-2026-58052 #7ZIP #CVE

    Post summary

    The user notes that 7‑Zip has an unresolved vulnerability (CVE‑2026‑58052) referenced via the NVD link, with no further technical information or exploitation context.

    00051273
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-58052 Mark-of-the-Web Bypass in 7-Zip for Windows Through Version 26.02 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58052

    Post summary

    The text announces CVE-2026-58052, a Mark‑of‑the‑Web bypass vulnerability affecting 7‑Zip for Windows through version 26.02, without providing detailed technical info, PoC, or mitigation advice.

    00010138
    4.1K followersView on X
  • Windows_Waza@Windows_Waza
    Patch

    7-Zip 26.03 が公開され、Mark-of-the-Web(MOTW)が正しく保持されない脆弱性「CVE-2026-58052」が修正されました。 26.02 では任意コード実行につながる脆弱性も修正されています。 古い 7-Zip は最新版への更新をおすすめします。 https://windows-waza.com/serious-vulnerability-in-older-version-of-7-zip-update-immediately/ #7Zip #Windows11

    Post summary

    This notice announces that 7‑Zip 26.03 has been released, addressing CVE‑2026‑58052 (MOTW issue) and earlier arbitrary‑code‑execution flaws, and urges users of older versions to upgrade.

    00000133
    112 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting 7-Zip (CVE-2026-58052) https://vuldb.com/vuln/374508/cti

    Post summary

    The post alerts that elevated activity targeting 7‑Zip’s CVE‑2026‑58052 is being observed in the wild, but no exploit code, patch, or technical details are cited.

    00000119
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App7-zip7-zip---

Explore more