CVE-2026-14191Patch

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 10 signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 6 mentions (2026-07-02); latest day: 1
  • 12 total mentions across 7 days

Deep dive

Activity timeline12 mentions / 7d
02356Mentions · 2026-07-01: 1Mentions · 2026-07-02: 6Mentions · 2026-07-03: 1Mentions · 2026-07-04: 1Mentions · 2026-07-09: 1Mentions · 2026-07-21: 1Mentions · 2026-08-05: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-02: 6Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 5Technical Details · 2026-07-03: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-09: 1Technical Details · 2026-08-05: 107-0107-0207-0307-0407-0907-2108-05
Signal classification2 categories
Patch
975.0%
Disclosure
325.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-07-011
Disclosure1
2026-07-026
Patch6
2026-07-031
Disclosure1
2026-07-041
Patch1
2026-07-091
Patch1
2026-07-211
Disclosure1
2026-08-051
Patch1
Full discourse12 posts
  • Cyber Security News@The_Cyber_News
    Patch

    🛡️ WinRAR Vulnerability Could Allow Attackers to Take Control of Your Computer Source: https://cybersecuritynews.com/winrar-7-23-fixes-heap-overflow-vulnerability/ WinRAR 7.23 addresses a newly disclosed heap overflow vulnerability in the RAR5 recovery volume processing code, tracked as CVE-2026-14191. Closing a memory-corruption flaw that could be triggered by malicious recovery volume (.rev) data and potentially lead to application crashes or further exploitation. WinRAR 7.23 is a security-focused maintenance release that primarily fixes two vulnerabilities impacting archive handling and extraction safety. The most critical issue is a heap overflow in the RAR5 recovery volume data reconstruction logic, which affects WinRAR, command-line RAR, and UnRAR components. #cybersecuritynews

    Post summary

    The post reports CVE‑2026‑14191, a heap overflow in WinRAR’s recovery volume handling, and indicates that the WinRAR 7.23 update provides the necessary fix.

    65612024618.0K
    72.5K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    اصدقائي مستخدمين ويندوز اكيد مثبتين تستخدم WinRAR صح ؟ حدّثوه إلى الإصدار 7.23 الآن. فيه ثغرة برقم CVE-2026-14191 ممكن تسبب اختراق لجهازك https://t.co/pnsDWH3aFl

    Post summary

    The tweet warns about CVE-2026-14191 and urges Windows users to update WinRAR to version 7.23 to mitigate potential intrusion.

    25048205.8K
    50.1K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    WinRARにヒープオーバーフローの脆弱性。CVE-2026-14191はCVSSスコア7.8で、RAR5回復ボリュームのパーサにおける検証不備。UnRAR.dllは回復ボリュームの処理を割愛するため無事。WinRAR 7.23で修正。 https://securityonline.info/winrar-vulnerability-cve-2026-14191/

    Post summary

    The text reports a heap overflow in WinRAR's RAR5 recovery volume parser (CVE‑2026‑14191) with a CVSS of 7.8, and confirms the flaw is fixed in WinRAR 7.23.

    040511.1K
    7.7K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A WinRAR vulnerability (CVE-2026-14191) causes a heap overflow via crafted .rev recovery files. Update WinRAR and UnRAR to version 7.23 now. #WinRAR #UnRAR #CVE202614191 #HeapOverflow #RAR5 #RARLAB #Vulnerability https://securityonline.info/winrar-vulnerability-cve-2026-14191 https://t.co/EX7KU1NkEz

    Post summary

    WinRAR CVE‑2026‑14191 is a heap‑overflow flaw triggered by crafted ".rev" recovery files; users should upgrade to version 7.23 to remediate.

    02062643
    12.9K followersView on X
  • Anti-Malware.Ru@Anti_Malware
    Patch

    RARLAB выпустила WinRAR 7.23 и закрыла уязвимость CVE-2026-14191, связанную с обработкой восстановительных томов RAR5. Проблема затрагивает WinRAR, RAR и UnRAR до версии 7.23. https://www.anti-malware.ru/news/2026-07-02-111332/50557 https://t.co/fxUqsxlWqh

    Post summary

    RARLAB has fixed CVE‑2026‑14191 in WinRAR 7.23, addressing a flaw in RAR5 recovery volume handling. No evidence of PoC, exploit tools, or active exploitation is provided.

    00012128
    3.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    14:19 UTC: CVE-2026-14191 disclosed. 🛡️ WinRAR Vulnerability Could Allow Attackers to Take Control of Your Computer Source: WinR Source: X search for CVE-2026 critical Posted: 2026-07-02T14:19:16.000Z Likes: 37

    Post summary

    The post announces the new WinRAR vulnerability CVE‑2026‑14191, noting it could allow attackers to take control of a computer, but provides no further technical or exploit information.

    1000044
    326 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-14191 - OOB heap write in #WinRAR RAR5 .rev parser. CVSS 7.8. Attackers can corrupt memory via crafted .rev files. Update immediately. #CVEAlert #infosec #cybersecurity #windows #resteam #blueteam #sysadmin #linix more info: https://www.valtersit.com/cve/CVE-2026-14191

    Post summary

    A new CVE-2026-14191 vulnerability—a 7.8‑scored out‑of‑bounds heap write in WinRAR’s RAR5 .rev parser—has been disclosed, and users are urged to update immediately to mitigate memory corruption risks.

    00010115
    968 followersView on X
  • SecEngCyGy@snypet86
    Patch

    WinRAR 7.23 fixes CVE-2026-14191: heap overflow in RAR5 recovery volumes. No auto-update. Crafted .rev can corrupt memory. Update to 7.23; don't repair untrusted archives on old builds. https://www.win-rar.com/whatsnew.html #CyberSecurity

    Post summary

    The advisory confirms that WinRAR 7.23 addresses CVE‑2026‑14191, a heap overflow in RAR5 recovery volumes, and recommends updating to 7.23 and avoiding untrusted archives on older builds.

    0000040
    23 followersView on X
  • iototsecnews@iototsecnews
    Patch

    WinRAR の脆弱性 CVE-2026-14191 が FIX:ヒープオーバーフローによるクラッシュに対応 https://iototsecnews.jp/2026/07/02/winrar-7-23-fixes-heap-overflow-vulnerability-that-leads-to-application-crashes/ WinRAR において、圧縮ファイルを修復する特別なデータを読み込む際に、割り当てられたメモリ領域を超えて書き込みが発生してしまう深刻な欠陥 CVE-2026-14191 が公表されました。この問題の背景には、破損したデータを復元するための処理ロジックにおいて、受け入れる情報のサイズや境界線を厳密に検証しきれない仕組み上の隙があります。もしこの弱点を悪用された場合には、利用中のツールが強制終了させられたり、他の不具合と組み合わされることでコンピュータ内で不正な命令を勝手に実行されたりする、重大な被害が生じる恐れがあります。確実な対応策として、まずは導入している解凍ソフトのバージョンを確認し、最新の修正版へ速やかに更新してください。 #CVE202614191 #Vulnerability #WinRAR

    Post summary

    The article announces that WinRAR CVE-2026-14191, a heap‑overflow flaw that can crash the application or potentially lead to code execution, has been fixed and urges users to update to the latest version.

    00000139
    500 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 WinRAR 723 Emergency Patch: #CVE-2026-14191 Heap Overflow Opens Door to Remote Code Execution—Are You Protected? + Video https://undercodetesting.com/winrar-723-emergency-patch-cve-2026-14191-heap-overflow-opens-door-to-remote-code-execution-are-you-protected-video/ Educational Purposes!

    Post summary

    The message announces an emergency patch for WinRAR 723 addressing CVE‑2026‑14191, a heap‑overflow remote code execution vulnerability, but provides no PoC or exploit details.

    0000057
    652 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: New #vulnerability in #WinRAR. CVE-2026-14191 CVSS: 7.8. Opening a crafted collection of RAR5 recovery-volumes could result in Remote Code Execution #RCE. Please use caution when opening files from external sources. Read https://www.win-rar.com/whatsnew.html?&L=0 and #Patch #Patch #Patch

    Post summary

    The text announces a new WinRAR vulnerability (CVE-2026-14191) with technical details and directs users to the vendor’s patch advisory.

    00000352
    7.2K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    WinRAR 7.23 fixes a critical heap overflow vulnerability (CVE-2026-14191) in RAR5 recovery volume processing. Users should update promptly to enhance security and stability. #WinRAR #SecurityUpdate #CVE202614191 #CyberSecurity #SoftwareUpdate #DataProtection https://thedailytechfeed.com/winrar-7-23-addresses-critical-heap-overflow-vulnerability/

    Post summary

    The tweet announces WinRAR 7.23 updating a critical heap‑overflow vulnerability (CVE‑2026‑14191) and urges users to apply the patch promptly for security and stability.

    0000077
    467 followersView on X

Explore more