CVE-2023-40477
✓ Confirmed 0-Day
Triaged: March 20, 2026
3 articles
EPSS Score
Source: FIRST.org · 2026-05-24
91.89%
probability
This CVE has a 91.89% probability
of being exploited in the next 30 days.
0%
Top 99.7th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
wildptr-io/Winrar-CVE-2023-40477-POC
CVE-2023-40477 PoC by Wild-Pointer
24
winkler-winsen/Scan_WinRAR
Scan for WinRAR files affected to CVE-2023-40477
0
2 repos — triés par ⭐
Rechercher sur GitHub ↗
WinRAR zero-day exploited since April to hack trading accounts
BleepingComputer
Aug 23, 2023
Signal Intelligence
Confidence
85%
EPSS
91.89%
Mentions
3
Last Seen
Aug 23, 2023
CNA Information
Analyst Note
Article [1] explicitly states 'WinRAR zero-day exploited since April', confirming in-the-wild exploitation. The CVE-2023-40477 is from 2023 and demonstrates active attacks against real targets (trading accounts) with clear timing documentation of exploitation preceding broader disclosure.
Triage Info
Decided atMar 20, 2026