CVE-2026-25961

SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and executes installers without signature checks. A network attacker with any valid TLS certificate (e.g., Let's Encrypt) can intercept the update check request, inject a malicious installer URL, and achieve arbitrary code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sumatrapdfreader:sumatrapdf:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-09 22:16

Updated : 2026-02-20 20:22


NVD link : CVE-2026-25961

Mitre link : CVE-2026-25961

CVE.ORG link : CVE-2026-25961


JSON object : View

Products Affected

sumatrapdfreader

  • sumatrapdf
CWE
CWE-295

Improper Certificate Validation

CWE-494

Download of Code Without Integrity Check