
We've released Beyond Compare 5.2.6.32774. General polish, stability improvements, and vulnerability fixes. Updated 7-zip to 26.03. Fixes CVE-2026-58052.
Exploitation ongoing with high activity in latest observed window (1 mentions)
Recommended action window: Immediate (within 24h)
NVD description
7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with ZoneId=0. A second STM record named '::$DATA' overwrites the extracted file's default data stream, letting an attacker defeat SmartScreen/MotW warnings and spoof file content.
Priority
MEDIUM
Exploitation
ACTIVE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-06-28 | 2 | Active Exploitation1Disclosure1 |
| 2026-07-30 | 1 | General1 |
| 2026-09-04 | 1 | Patch1 |

We've released Beyond Compare 5.2.6.32774. General polish, stability improvements, and vulnerability fixes. Updated 7-zip to 26.03. Fixes CVE-2026-58052.

Windows環境では7-Zipを長らく愛用してるけど、最新版でも未解決の脆弱性が公開されているな…。 https://nvd.nist.gov/vuln/detail/CVE-2026-58052 #7ZIP #CVE
Post summary
The user notes that 7‑Zip has an unresolved vulnerability (CVE‑2026‑58052) referenced via the NVD link, with no further technical information or exploitation context.

CVE-2026-58052 Mark-of-the-Web Bypass in 7-Zip for Windows Through Version 26.02 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58052
Post summary
The text announces CVE-2026-58052, a Mark‑of‑the‑Web bypass vulnerability affecting 7‑Zip for Windows through version 26.02, without providing detailed technical info, PoC, or mitigation advice.

7-Zip 26.03 が公開され、Mark-of-the-Web(MOTW)が正しく保持されない脆弱性「CVE-2026-58052」が修正されました。 26.02 では任意コード実行につながる脆弱性も修正されています。 古い 7-Zip は最新版への更新をおすすめします。 https://windows-waza.com/serious-vulnerability-in-older-version-of-7-zip-update-immediately/ #7Zip #Windows11
Post summary
This notice announces that 7‑Zip 26.03 has been released, addressing CVE‑2026‑58052 (MOTW issue) and earlier arbitrary‑code‑execution flaws, and urges users of older versions to upgrade.

Attention, elevated activities detected targeting 7-Zip (CVE-2026-58052) https://vuldb.com/vuln/374508/cti
Post summary
The post alerts that elevated activity targeting 7‑Zip’s CVE‑2026‑58052 is being observed in the wild, but no exploit code, patch, or technical details are cited.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | 7-zip | 7-zip | - | - | - |