WinRAR

RARLAB (win.rar GmbH) · current 7.23.0

Are you RARLAB (win.rar GmbH)? Claim this page

The current version of WinRAR is 7.23.0 (as of 18/08/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2025-8088RARLAB WinRAR Path Traversal VulnerabilityRansomware

    8.8 high · over the network, without login, needs user action · CISA deadline was 2 Sept 25

  • CVE-2018-20250WinRAR Absolute Path Traversal VulnerabilityRansomware

    7.8 high · locally only, without login, needs user action · CISA deadline was 15 Aug 22

  • CVE-2023-38831RARLAB WinRAR Code Execution VulnerabilityRansomware

    7.8 high · locally only, without login, needs user action · CISA deadline was 14 Sept 23

  • CVE-2025-6218RARLAB WinRAR Path Traversal Vulnerability

    7.8 high · locally only, without login, needs user action · CISA deadline was 30 Dec 25

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

WinRAR at a glance

WinRAR from RARLAB, distributed by win.rar GmbH, is a Windows archiver that creates RAR and ZIP archives and extracts many further formats. It handles multi-volume archives, recovery records and encrypted archives, which is why it is found on workstations and servers alike. Administrators also use the command-line build to script backups and packaging steps.

New versions appear at irregular intervals; besides feature work they regularly carry corrections to the extraction routines. Because WinRAR opens archives from untrusted sources — typically mail attachments — such flaws have been actively exploited in the past. The bundled library used to extract 7z archives is refreshed along with them.

When updating, note that WinRAR has no automatic updater: without software distribution, old installations simply stay behind. Licences carry across versions, so moving up costs nothing. Take installers only from the vendor, as counterfeit packages circulate; in fleets, deploy through package management and inventory which builds are actually present.

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
7.23.0STABLE18/08/2026Release notes →

Frequently asked questions

What is the latest version of WinRAR?
WinRAR 7.23.0, released 18/08/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the WinRAR release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new WinRAR updates?
Tick WinRAR off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new WinRAR version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current WinRAR version and keeps it up to date. Anyone may embed it, no account needed.

WinRAR badge
[![WinRAR](https://patchletter.com/badge/winrar.svg)](https://patchletter.com/en/software/winrar)
https://patchletter.com/badge/winrar.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Admin Tools