CybersecuritySoftware Guides

Critical 7-Zip Security Flaws Expose Users to Remote Code Execution Attacks

Security researchers have identified two critical directory traversal vulnerabilities in 7-Zip that could allow attackers to execute malicious code on vulnerable systems. These flaws affect millions of users who haven’t updated to the patched versions released this summer.

Security experts are sounding the alarm about two critical security vulnerabilities in the popular 7-Zip file archiver that could put millions of users at risk of remote code execution attacks. The flaws, tracked as CVE-2025-11001 and CVE-2025-11002, represent serious threats to both individual users and organizations relying on this widely-used compression tool.

Understanding the 7-Zip Security Crisis