RARLAB known exploited vulnerabilities
CISA lists 5 RARLAB CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2025-12-09), and 4 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2023-38831 (WinRAR): EPSS 99.8%, added 2023-08-24
- CVE-2022-30333 (UnRAR): EPSS 99.1%, added 2022-08-09
- CVE-2018-20250 (WinRAR): EPSS 96.0%, added 2022-02-15
- CVE-2025-8088 (WinRAR): EPSS 94.1%, added 2025-08-12
- CVE-2025-6218 (WinRAR): EPSS 90.5%, added 2025-12-09
Most affected RARLAB products
WinRAR (4), UnRAR (1).
All RARLAB CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-6218 | WinRAR | WinRAR Path Traversal | 2025-12-09 | 2025-12-30 | 90.5% | – |
| CVE-2025-8088 | WinRAR | WinRAR Path Traversal | 2025-08-12 | 2025-09-02 | 94.1% | Yes |
| CVE-2023-38831 | WinRAR | WinRAR Code Execution | 2023-08-24 | 2023-09-14 | 99.8% | Yes |
| CVE-2022-30333 | UnRAR | UnRAR Directory Traversal | 2022-08-09 | 2022-08-30 | 99.1% | Yes |
| CVE-2018-20250 | WinRAR | WinRAR Absolute Path Traversal | 2022-02-15 | 2022-08-15 | 96.0% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors