← Back to Feed
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
CVE-2025-8088
June 8, 2026 · Trend Micro · Severity: HIGH
Trend Micro reports that two Russia-aligned campaigns are still exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian organizations, almost a year after it was patched. This demonstrates how unmanaged software can leave exploited entry points open long after fixes are shipped.
Key Takeaways
- Russia-aligned campaigns exploit old WinRAR flaw CVE-2025-8088 against Ukrainian organizations.
- The vulnerability is exploited nearly a year after the patch was released.
- Unmanaged software keeps entry points open long after fixes are available.