logo

Active Exploitation of 7-Zip RCE Vulnerability Shows Why Manual Patching is No Longer an Option 

ID: 5e969de3-2e6e-5ab2-b107-3280a2aac658

STIX ID: report--5e969de3-2e6e-5ab2-b107-3280a2aac658

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2025-12-04

Date Updated: 2026-04-28

Author: Mohd Anas Khan

...
...

A critical remote code execution vulnerability in 7-Zip (CVE-2025-11001) arising from improper symbolic-link handling in ZIP archives is being actively exploited; it has CVSS v3 7.0, affects versions prior to 25.0.0 (with a related CVE-2025-11002), and has been observed across sectors such as healthcare and finance with an NHS advisory urging immediate updates. The report urges updating to 7-Zip 25.00 or later and highlights Qualys Patch Management as an automated remediation approach to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.