← Vulnerability feed

Vulnerability record · CVE-2026-25961 · published 9 February 2026

CVE-2026-25961: Sumatrapdfreader sumatrapdf improper certificate validation vulnerability

Sumatrapdfreader · Sumatrapdf

SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and executes installers without signature checks. A network attacker with any valid TLS certificate (e.g., Let's Encrypt) can intercept the update check request, inject a malicious installer URL, and achieve arbitrary code execution.

7.5 CVSS 3.1 High EPSS 0.44% · top 64.3% CWE-295 · Improper certificate validationCWE-494 · Download of code without integrity check
7.5CVSS 3.1 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and executes installers without signature checks. A network attacker with any valid TLS certificate (e.g., Let's Encrypt) can intercept the update check request, inject a malicious installer URL, and achieve arbitrary code execution.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25961 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2012-4895Sumatrapdfreader sumatrapdf memory buffer overflow vulnerabilityHeap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnera…EPSS 5.2%9.3CVE-2012-4896Sumatrapdfreader sumatrapdf memory buffer overflow vulnerabilityHeap-based buffer overflow in SumatraPDF before 2.1 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnera…EPSS 5.2%9.3CVE-2009-4117Sumatrapdfreader sumatrapdf memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attacke…EPSS 7.8%7.8CVE-2026-25880Sumatrapdfreader sumatrapdf untrusted search path vulnerabilitySumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located i…EPSS 0.20%7.8CVE-2026-23512Sumatrapdfreader sumatrapdf untrusted search path vulnerabilitySumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting i…EPSS 0.22%7.8CVE-2012-5340Sumatrapdfreader sumatrapdf integer overflow vulnerabilitySumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.EPSS 5.7%7.8CVE-2013-2830Sumatrapdfreader sumatrapdf use after free vulnerabilityUse-after-free vulnerability in SumatraPDF Reader 2.x before 2.2.1 allows remote attackers to execute arbitrary code via a crafted PDF file.EPSS 3.6%7.3CVE-2025-57248Sumatrapdfreader sumatrapdf null pointer dereference vulnerabilityA null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is opened, t…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2026-25961), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.