logo

CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks

ID: c40840ae-7842-5cd2-ae33-ef9cc80fb323

STIX ID: report--c40840ae-7842-5cd2-ae33-ef9cc80fb323

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-10

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical WinRAR zero-day (CVE-2025-6218) path-traversal vulnerability is being actively exploited to allow remote code execution by extracting files outside intended folders; the flaw carries a CVSS 9.8 rating and was added to CISA's Known Exploited Vulnerabilities catalog—users and organizations are urged to update WinRAR immediately or discontinue use until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.