high
CISA KEV
CVE-2025-8088
RARLAB WinRAR Path Traversal Vulnerability
// Description
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
// Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal remediation due Sep 2, 2025 — past due
Advertisement
// Coverage
- Turla's STOCKSTAY Backdoor: Analysis of Campaigns & WinRAR Exploit
Jun 26, 2026
- CVE-2025-8088: Russia-Aligned Groups Exploit WinRAR Flaw in Ukraine
Jun 9, 2026
- Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine
Jun 2, 2026
- 2025 Zero-Day Exploitation Review: Enterprise & OS Targets Dominate
Mar 5, 2026