Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
2026-07-19T07:23:24Z•a3d6d9e9eab1adf8afa5af5da46ece024d0869116c45e0d2e9cc41582c649dee
7-ZipACR StealerAnthropicClaudeFortinetHollowByteLegacyHiveOpenSSLWindowsWordPresscredential theftdata breachdenial of serviceincident responsemacOSmalwarepatchingprivilege escalationransomwarerceremote code executionsupply chainzero-day
What happened
Collection of mid-July 2026 security reports covering multiple high-impact vulnerabilities, active exploitation, and breaches. Notable items: 7‑Zip 26.02 fixes a remote code execution (RCE) bug; WordPress Core “wp2shell” RCE now has public exploits; Microsoft warns of a surge in ACR Stealer credential-theft campaigns; a Windows zero-day dubbed LegacyHive enables local privilege escalation to admin; CISA orders rapid patching for actively exploited Fortinet FortiSandbox flaws; HollowByte is a small-payload OpenSSL DoS; macOS ClickLock and a Claude Chrome-extension abuse flaw enable credential/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a3d6d9e9eab1adf8afa5af5da46ece024d0869116c45e0d2e9cc41582c649dee
- Enrichment time
- 2026-07-19T07:23:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.