PatchSiren cyber security CVE debrief
CVE-2026-88361 SumatraPDF CVE debrief
CVE-2026-88361 is an integer overflow vulnerability in SumatraPDF 3.6.1 when parsing PDF PageLabels /Nums entries. Defenders should assess exposure, prioritize remediation, and verify SumatraPDF versions. This vulnerability exists in the EngineMupdf::BuildPageLabelRec() function and may impact organizations using affected versions of SumatraPDF. It is recommended to review the official CVE record and vendor guidance for further information on affected scope, severity, and remediation steps.
- Vendor
- SumatraPDF
- Product
- SumatraPDF
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for managing and securing SumatraPDF installations should assess exposure and prioritize remediation. This includes IT administrators, security teams, and vulnerability management personnel who oversee software updates and patch management for SumatraPDF. Additionally, operators and users of SumatraPDF 3.6.1 may need to verify software versions and apply patches or updates to prevent exploitation.
Why it matters
CVE-2026-88361 is an integer overflow vulnerability in SumatraPDF 3.6.1 when parsing PDF PageLabels /Nums entries. Defenders should assess exposure, prioritize remediation, and verify SumatraPDF versions.
- Verify SumatraPDF versions to identify potential vulnerability
- Remediate vulnerable SumatraPDF 3.6.1 instances to prevent exploitation
- Monitor for potential exploitation attempts
Technical summary
The vulnerability exists in the EngineMupdf::BuildPageLabelRec() function when parsing PDF PageLabels /Nums entries in SumatraPDF 3.6.1. This function is responsible for processing page labels in PDF files, and the integer overflow could potentially lead to arbitrary code execution or denial of service. Defenders should focus on remediating vulnerable SumatraPDF 3.6.1 instances and verifying software versions to prevent exploitation attempts. The CVE record provides limited technical details, so defenders should review the official advisory and source references for further information.
Defensive priority
Remediate vulnerable SumatraPDF 3.6.1 instances
Recommended defensive actions
- Inventory SumatraPDF installations to identify potentially vulnerable instances
- Prioritize remediation of vulnerable SumatraPDF 3.6.1 instances
- Verify SumatraPDF versions and apply patches or updates
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE description, official CVE record, and multiple GitHub source references identify SumatraPDF 3.6.1 as the impacted software. However, the exact scope of affected versions and potential variations in exploitation is not detailed in the CVE record. Defenders should verify SumatraPDF versions and review source references for additional information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-88361 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-88361
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-88361 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88361
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/chenjiefeng2001/sumatrapdf_folked/commit/b22a8c71ddc9de80ece5f88d14b434c20fee912e
-
Source reference
Unverified legacy reference
URL: https://github.com/haimag/sumatrapdf/commit/8b999ff1bf0a8df244e75440682a3fd9a038eb2d
-
Source reference
Unverified legacy reference
URL: https://github.com/sumatrapdfreader/sumatrapdf/issues/5952
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.