7 Zip is a widely used, open-source file archiver and compression utility with a modest but persistent vulnerability footprint. Despite a small product portfolio centered on the 7 Zip archiver itself and its POSIX variant p7zip, the software maintains prominence in the landscape owing to its ubiquitous deployment across consumer and enterprise systems for handling compressed archives. The vendor's disclosures span a range of parsing and decompression logic that reflects the complexity of supporting multiple archive formats and compression algorithms. Defenders should monitor this vendor's releases given the file-handling role of the software and its position as a common attack surface for malicious archive delivery; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 7 Zip over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-0411HIGH 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User i | Jan 25, 2025 | 7.0 | 89 | YES | NO |
CVE-2023-31102HIGH Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. | Nov 3, 2023 | 7.8 | 65 | NO | NO |
CVE-2025-11001HIGH 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7- | Nov 19, 2025 | 7.8 | 58 | NO | YES |
CVE-2026-48095HIGH 7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed s | Jun 5, 2026 | 8.8 | 37 | NO | NO |
CVE-2023-40481HIGH 7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | May 3, 2024 | 7.8 | 37 | NO | NO |
CVE-2024-11477HIGH 7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Nov 22, 2024 | 7.8 | 34 | NO | NO |
CVE-2016-2335HIGH The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or exec | Jun 7, 2016 | 8.8 | 33 | NO | NO |
CVE-2016-2334HIGH Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HF | Dec 13, 2016 | 7.8 | 32 | NO | NO |
CVE-2007-4725MEDIUM Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute | Sep 5, 2007 | 6.8 | 31 | NO | YES |
CVE-2008-6536HIGH Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10). | Mar 30, 2009 | 10.0 | 30 | NO | NO |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 7 Zip.
Media articles that mention a CVE ID that affects a product developed by 7 Zip — matched by CVE ID, not by vendor name.