A newly published WinRAR vulnerability, CVE-2026-14191, lets a specially crafted set of archive files write data where it should not, which can lead to an attacker running code on your PC. RARLAB has fixed it in version 7.23, but WinRAR does not update itself, so every copy stays vulnerable until someone downloads the new version by hand.
What happened
The US National Vulnerability Database published CVE-2026-14191 on 1 July 2026. NVD describes it as an out-of-bounds heap write in the parser for RAR5 recovery volumes, the .rev files used to reconstruct data in multi-part archives. It affects WinRAR and RAR “versions before 7.23”.
RARLAB’s release notes for 7.23 put it in one line: “Heap overflow vulnerability is fixed in RAR5 recovery volume data reconstruction code”.
Malwarebytes, writing on 2 July, explained the risk in plain terms: “An attacker can craft a set of two or more .rev files that make WinRAR write data outside the memory it has allocated”. Writing outside allocated memory is the kind of bug that can crash a program or, in the worst case, let an attacker take control of it. I will leave the technical details there.
The good news for now is that no active exploitation was reported at disclosure. That makes now the right moment to update, while no attacks have been reported.
The same 7.23 release contains a second fix. RARLAB says that when extracting crafted archives, a “Symbolic link pointing outside of destination folder could be created”. In simple terms, an archive could place a shortcut that points somewhere outside the folder you chose to extract into. It is a different problem from the heap overflow, and the same update closes both.
Who is affected
Anyone running WinRAR or the RAR command-line tool older than version 7.23. That covers home users, offices and IT teams that installed WinRAR years ago and never touched it again.
The NVD scoring gives a clear picture of how an attack would work at a high level. The attack vector is local and user interaction is required, which means the victim has to open the malicious files. In practice that usually means an archive arriving by email, a messaging app or a download link. Nothing happens if you never open it. But if you do, the impact on confidentiality, integrity and availability is rated high.
By the numbers
| Item | Detail |
|---|---|
| CVE | CVE-2026-14191 |
| NVD publication date | 1 July 2026 |
| CVSS 3.1 score | 7.8 (HIGH) |
| Attack vector | Local, user interaction required |
| Affected versions | WinRAR and RAR before 7.23 |
| Fixed version | 7.23 |
| Fixes in 7.23 covered here | 2 (heap overflow, symbolic link) |
| Exploitation reported at disclosure | None |
The full CVSS vector from NVD is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. For non-specialists: low attack complexity, no privileges needed, the user must take an action, and a successful attack has high impact.
What to do now
- Download WinRAR 7.23 or later from rarlab.com. If your copy is older than 7.23, get the new one from the official site, not from a download portal or a link in an email. Because WinRAR does not update itself, this is the only way to get the fix.
- Do not open archives you did not expect. Be especially careful with multi-part sets that include .rev files. A friend’s name on the message is not proof it came from them.
- IT admins: inventory and trim. Find every machine with WinRAR installed, update the ones that need it, and remove it where it is not needed. Fewer copies means fewer forgotten old versions.
- Keep anti-malware protection running and up to date. It is a second line of defence if a malicious archive gets opened anyway.
Why it matters
WinRAR is on a large share of home and office PCs in our region. It is often installed once, when the computer is new, and then forgotten. That is exactly why this matters: a browser or an operating system patches itself in the background, but WinRAR waits for you.
What caught my attention is how ordinary the attack path is. Archives are how many of us receive invoices, CVs, photos and project files. We are used to double-clicking them without thinking. A bug in the part of WinRAR that repairs archives turns that everyday habit into the entry point.
Past WinRAR flaws have been abused long after fixes were available, precisely because so many old copies stay installed. In my view, the right response is not panic, since there is no reported attack yet. It is a five-minute task: check the version, update from rarlab.com, and tell the one person in your family or office who installs everything and updates nothing.
Sources
- National Vulnerability Database (NIST), CVE-2026-14191 detail, published 1 July 2026, https://nvd.nist.gov/vuln/detail/CVE-2026-14191
- RARLAB, What’s new in the latest version, WinRAR 7.23 release notes, accessed 2 July 2026, https://www.rarlab.com/rarnew.htm
- Malwarebytes, WinRAR flaw could allow attackers to take control of your computer, 2 July 2026, https://www.malwarebytes.com/blog/news/2026/07/winrar-flaw-could-allow-attackers-to-take-control-of-your-computer