Exploitation of 2025 WinRAR Vulnerability Due to Lack of Updates

Exploitation of 2025 WinRAR Vulnerability Due to Lack of Updates

First seen 2 Feb 2026, 12:49 UTC Xda-DevelopersMsn 24.5

Article Content

Browse articles
ThreatCluster

A vulnerability identified as CVE-2025-8088 in WinRAR allows attackers to hide malware in archives that can install malicious payloads to the startup app folder. This exploit was patched in April 2025, but many users have not updated their applications, leaving them vulnerable to attacks. Criminals are actively exploiting this flaw as users continue to neglect updates.