CVE-2026-25961: SumatraPDF Update MITM -> Arbitrary Code Execution
SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNETFLAGIGNORECERTCNINVALID) and executes installers without signature checks. A network attacker with any valid TLS certificate (e.g., Let's Encrypt) can intercept the update check request, inject a malicious installer URL, and achieve arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25961?
CVE-2026-25961 is classified with high severity due to its potential for arbitrary code execution.
How do I fix CVE-2026-25961?
To mitigate CVE-2026-25961, users should update SumatraPDF to version 3.5.3 or later, which addresses the vulnerability.
What are the risks associated with CVE-2026-25961?
The risks of CVE-2026-25961 include potential arbitrary code execution by an attacker due to insufficient security in the update mechanism.
Who is affected by CVE-2026-25961?
CVE-2026-25961 affects users of SumatraPDF versions 3.5.0 to 3.5.2 on Windows operating systems.
What is the cause of CVE-2026-25961?
The cause of CVE-2026-25961 is the disabling of TLS hostname verification and lack of signature checks during the update process.