Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

2026-07-19T13:23:26Zb2493d3d3085d77f5cf73df7d6c25b9e3adf2c89b77914f1e5af90f206223d78
7-zipabbottacr-stealeranthropic-claudechrome-extensioncisaclicklockcredential-theftdosernst-and-youngfairlifefortinetfortisandboxhollowbytelegacyhivemacos-malwareopensslprivilege-escalationpublic-exploitransomwarercesupply-chain-data-breachwindows-zero-daywordpresswp2shell

What happened

Multiple high-impact security developments: 7‑Zip 26.02 fixes an RCE in malicious archives and should be updated immediately; WordPress Core "wp2shell" RCE now has public exploits—admins must patch; CISA warns to urgently remediate two actively exploited Fortinet FortiSandbox flaws; a Windows zero‑day (LegacyHive) enables local privilege escalation; HollowByte is a small-payload OpenSSL DoS; Microsoft reports a surge in ACR Stealer credential‑theft attacks; new macOS ClickLock info‑stealer and a Claude Chrome extension flaw that lets malicious extensions trigger AI actions were disclosed; and,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b2493d3d3085d77f5cf73df7d6c25b9e3adf2c89b77914f1e5af90f206223d78
Enrichment time
2026-07-19T13:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.