SecAlerts
WinRAR logo

WinRAR

Security Risk Profile

71
/100
high

Security Risk Score

Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 23, 2023 to present

17
Total CVEs
2
Critical+High
5
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
7.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
71/100
high
⚠️ 5 Active Exploits 5 Zero-Days📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
2
Medium
1
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Out-of-bounds Read
1
2
Input Validation
1
3
Malicious File Upload
1

Most Affected Products

1. WinRAR WinRAR18
2. Roundcube Roundcube3
3. WinRAR UnRAR2
4. Microsoft Outlook2
5. WinRAR2

Recent Vulnerabilities

See more →
https://reddit.com/r/sysadmin/comments/1usrrjf/another_winrar_rce_today_and_it_still_has_no/
unknown

another WinRAR RCE today and it STILL has no auto-updater

7/10/2026🔧 No Patch
CVE-2026-14191
CVSS 7.8high

WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader

7/1/2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/winrar-path-traversal-flaw-still-exploited-by-numerous-hackers/
unknown

WinRAR path traversal flaw still exploited by numerous hackers

1/27/2026⚠ Exploited⚡ Zero-Day🔧 No Patch
https://www.bleepingcomputer.com/news/security/qilin-ransomware-abuses-wsl-to-run-linux-encryptors-in-windows/
unknown

Qilin ransomware abuses WSL to run Linux encryptors in Windows

10/28/2025🔧 No Patch
https://reddit.com/r/Malware/comments/1n7nwg2/the_winrar_0day_putting_socs_at_risk/
unknown

The WinRAR 0-day putting SOCs at risk

9/3/2025🔧 No Patch
https://www.theregister.com/2025/08/11/russias_romcom_among_those_exploiting/
unknown

Russia's RomCom among those exploiting a WinRAR 0-day in highly-targeted attacks

8/11/2025⚠ Exploited⚡ Zero-Day🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1mn8qpw/newly_discovered_winrar_exploit_linked_to_russian/
unknown

Newly discovered WinRAR exploit linked to Russian hacking group, can plant backdoor malware — zero day hack requires manual update to fix | WinRAR flaw CVE-2025-8088 has been fixed in version 7.13.

8/11/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/winrar-zero-day-flaw-exploited-by-romcom-hackers-in-phishing-attacks/
unknown

WinRAR zero-day exploited to plant malware on archive extraction

8/8/2025⚡ Zero-Day🔧 No Patch
CVE-2014-125119
CVSS 8.4high

WinRAR < 5.00 Filename Spoofing RCE

7/25/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/winrar-patches-bug-letting-malware-launch-from-extracted-archives/
unknown

WinRAR patches bug letting malware launch from extracted archives

6/25/2025🔧 No Patch

Monitor WinRAR in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.