Skip to content
Exploitation of WinRAR Path Traversal Flaw Continues Amid CISA Warning

Exploitation of WinRAR Path Traversal Flaw Continues Amid CISA Warning

First seen 27 Jan 2026, 22:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The CVE-2025-8088 vulnerability in WinRAR is being exploited by various threat actors for initial access and to deploy malware. The flaw allows attackers to use Alternate Data Streams to write malicious files to arbitrary locations, including the Windows Startup folder. In response to ongoing attacks, the vulnerability has been added to CISA's Known Exploited Vulnerabilities list, with federal agencies ordered to remediate it by December 30, 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

More articles in this cluster (12)

Following this threat?

Track CVE-2023-38831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed