CVE-2026-25961 affects SumatraPDF for Windows in versions 3.5.0 through 3.5.2. The vulnerable update mechanism disables TLS hostname verification by using INTERNET_FLAG_IGNORE_CERT_CN_INVALID during update checks, which causes the client to accept certificates whose common name/hostname does not match the intended update server. The updater also executes downloaded installers without verifying their digital signature. As a result, a network-positioned attacker who can intercept the update request and present any otherwise valid TLS certificate can tamper with the update response, supply a malicious installer URL, and cause SumatraPDF to download and execute attacker-controlled code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python proof-of-concept malicious update server for CVE-2026-25961 affecting SumatraPDF 3.5.0–3.5.2 on Windows. The vulnerability described is an insecure auto-update mechanism: TLS hostname validation is disabled during update checks and the downloaded installer is not verified (no signature/integrity validation). The PoC does not perform the interception itself; it assumes the attacker can redirect the victim’s request for the legitimate update-check file (www.sumatrapdfreader.org/update-check-rel.txt) to the attacker. Structure: - README.md: Explains the issue, affected versions, and high-level attack flow; suggests optional msfvenom generation of a malicious EXE. - SumatraPDF_CVE-2026-25961_PoC.py: Flask app that (1) serves a forged update-check response at /update-check-rel.txt advertising a fake version (999.9.9) and pointing Installer64 to the attacker’s /malicious_installer.exe, and (2) serves the payload executable at /malicious_installer.exe while logging the victim IP. If malicious_installer.exe is absent, it creates a dummy PE-like file (starts with 'MZ') as a placeholder. Exploit capabilities: - Network-delivered RCE chain component: provides the attacker-controlled update metadata and installer download endpoint. - Victim tracking: logs request.remote_addr for both update metadata and payload download. - Payload delivery: serves an arbitrary Windows executable under a plausible SumatraPDF installer filename. Operational notes: - Requires a MITM/DNS/traffic-redirection position and user interaction (victim clicks Install). The script listens on TCP port 5000 and uses HTTP URLs in the forged update response.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.