CVE-2025-6218
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
3 articles
EPSS Score
Source: FIRST.org · 2026-05-24
5.69%
probability
This CVE has a 5.69% probability
of being exploited in the next 30 days.
0%
Top 90.5th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
ignis-sec/CVE-2025-6218
A simple proof of concept for WinRAR Path Traversal | RCE | CVE-2025-6218
12
mulwareX/CVE-2025-6218-POC
RARLAB WinRAR Directory Traversal Remote Code Execution
11
2 repos — triés par ⭐
Rechercher sur GitHub ↗
Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088
TheHackerNews
Jan 28, 2026
Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups
TheHackerNews
Dec 10, 2025
Signal Intelligence
Confidence
85%
EPSS
5.69%
Mentions
3
Last Seen
Jan 28, 2026
CNA Information
Analyst Note
CVE-2025-6218 is confirmed as a zero-day: published June 21, 2025, with documented active exploitation by multiple threat actors reported by CISA and added to the KEV catalog, indicating in-the-wild attacks occurred before or concurrent with patch availability. The 2025 publication year and explicit CISA KEV listing citing 'active exploitation' strongly support zero-day classification.
Threat Actors 26
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
APT37
apt_group
Information theft and espionage
🇰🇵 KP
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Gamaredon Group
apt_group
Information theft and espionage
🇷🇺 RU
Dropping Elephant
apt_group
Information theft and espionage
🇮🇳 IN
HAZY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
ArcaneDoor
apt_group
🇨🇳 CN
VICEROY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
RomCom
apt_group
Financial gain
🇷🇺 RU
Opal Sleet
apt_group
🇰🇵 KP
UNC5174
apt_group
🇨🇳 CN
SNOWGLOBE
apt_group
Information theft and espionage
🇫🇷 FR
Returned Libra
apt_group
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Void Rabisu
apt_group
Financial gain
🇷🇺 RU
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
GOFFEE
apt_group
🇷🇺 RU
Red October
apt_group
🇷🇺 RU
Pat Bear
apt_group
🇸🇾 SY
Mana Team
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 05, 2026