CVE-2023-40477

✓ Confirmed 0-Day
Triaged: March 20, 2026 3 articles

EPSS Score

Source: FIRST.org · 2026-05-24
91.89%
probability
This CVE has a 91.89% probability of being exploited in the next 30 days.
0% Top 99.7th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Exploits & PoC

wildptr-io/Winrar-CVE-2023-40477-POC

CVE-2023-40477 PoC by Wild-Pointer

24
winkler-winsen/Scan_WinRAR

Scan for WinRAR files affected to CVE-2023-40477

0
2 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 91.89%
Mentions 3
Last Seen Aug 23, 2023

CNA Information

Analyst Note

Article [1] explicitly states 'WinRAR zero-day exploited since April', confirming in-the-wild exploitation. The CVE-2023-40477 is from 2023 and demonstrates active attacks against real targets (trading accounts) with clear timing documentation of exploitation preceding broader disclosure.

Triage Info

Decided atMar 20, 2026