CyberMax
Home › Exploited CVEs

RARLAB known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 RARLAB CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2025-12-09), and 4 are known to be used in ransomware campaigns.

RARLAB CVEs added to CISA KEV per year
2022: 2202222023: 1202312025: 220252

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected RARLAB products

WinRAR (4), UnRAR (1).

All RARLAB CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2025-6218WinRARWinRAR Path Traversal2025-12-092025-12-3090.5%–
CVE-2025-8088WinRARWinRAR Path Traversal2025-08-122025-09-0294.1%Yes
CVE-2023-38831WinRARWinRAR Code Execution2023-08-242023-09-1499.8%Yes
CVE-2022-30333UnRARUnRAR Directory Traversal2022-08-092022-08-3099.1%Yes
CVE-2018-20250WinRARWinRAR Absolute Path Traversal2022-02-152022-08-1596.0%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors