Vendor

RARLAB

As of , 5 RARLAB vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2018-20250.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2018-20250Absolute Path TraversalRARLAB WinRARPatch this weekRansomware use; Metasploit module; EPSS 0.96; verified Exploit-DB entry0.96
2CVE-2023-38831Code ExecutionRARLAB WinRARPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
3CVE-2022-30333Directory TraversalRARLAB UnRARPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
4CVE-2025-6218Path TraversalRARLAB WinRARPatch this weekEPSS 0.900.90
5CVE-2025-8088Path TraversalRARLAB WinRARPatch this weekRansomware use; EPSS 0.940.94

Products

Added each year

0.511.522022: 2220222023: 1120232024: nonenone20242025: 2220252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20222
20231
2024none
20252
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-8088 RARLAB WinRARRansomware use: Unknown to Known.
  2. CVE-2022-30333 RARLAB UnRARRansomware use: Unknown to Known.

Every change we recorded