Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
2026-07-19T13:23:26Z•b2493d3d3085d77f5cf73df7d6c25b9e3adf2c89b77914f1e5af90f206223d78
7-zipabbottacr-stealeranthropic-claudechrome-extensioncisaclicklockcredential-theftdosernst-and-youngfairlifefortinetfortisandboxhollowbytelegacyhivemacos-malwareopensslprivilege-escalationpublic-exploitransomwarercesupply-chain-data-breachwindows-zero-daywordpresswp2shell
What happened
Multiple high-impact security developments: 7‑Zip 26.02 fixes an RCE in malicious archives and should be updated immediately; WordPress Core "wp2shell" RCE now has public exploits—admins must patch; CISA warns to urgently remediate two actively exploited Fortinet FortiSandbox flaws; a Windows zero‑day (LegacyHive) enables local privilege escalation; HollowByte is a small-payload OpenSSL DoS; Microsoft reports a surge in ACR Stealer credential‑theft attacks; new macOS ClickLock info‑stealer and a Claude Chrome extension flaw that lets malicious extensions trigger AI actions were disclosed; and,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- b2493d3d3085d77f5cf73df7d6c25b9e3adf2c89b77914f1e5af90f206223d78
- Enrichment time
- 2026-07-19T13:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.