← Back to Feed

Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open

CVE-2025-8088

June 8, 2026 · Trend Micro · Severity: HIGH

Trend Micro reports that two Russia-aligned campaigns are still exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian organizations, almost a year after it was patched. This demonstrates how unmanaged software can leave exploited entry points open long after fixes are shipped.

Key Takeaways

  • Russia-aligned campaigns exploit old WinRAR flaw CVE-2025-8088 against Ukrainian organizations.
  • The vulnerability is exploited nearly a year after the patch was released.
  • Unmanaged software keeps entry points open long after fixes are available.
☕ Buy a Coffee