CVE-2025-8088
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
- Published Aug 8, 2025
- CVSS 8.4 high
- 94.1% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- Exploits and vulnerabilities in Q2 2026 Securelist ·
- STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus Google Threat Intelligence ·
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity ·
- APT and financial attacks on industrial organizations in Q3 2025 Kaspersky ICS CERT ·