WinRAR Zero-Day Exploit Actively Targeted in Ongoing Attacks

Users urged to update WinRAR version 7.13 to patch a critical vulnerability under active exploitation.

Critical zero-day CVE-2025-8088 patched

A newly discovered zero-day vulnerability in WinRAR, tracked as CVE-2025-8088, has been patched following reports of active exploitation in the wild. The flaw, with a CVSS severity score of 8.8, affects the Windows version of WinRAR and stems from a path traversal bug that enables arbitrary code execution through malicious archive files.

According to