CVE-2026-25865Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 4 mentions (2026-06-18); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-06-17: 2Mentions · 2026-06-18: 4Mentions · 2026-07-10: 1Mentions · 2026-07-17: 1Mentions · 2026-08-03: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-06-17: 2Technical Details · 2026-06-18: 3Technical Details · 2026-07-17: 1Technical Details · 2026-08-03: 106-1706-1807-1007-1708-03
Signal classification2 categories
Disclosure
777.8%
General
222.2%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-172
Disclosure2
2026-06-184
Disclosure4
2026-07-101
General1
2026-07-171
Disclosure1
2026-08-031
General1
Full discourse9 posts
  • Spektion@spektion
    General

    A signed binary. Clean on VirusTotal. Clean on every file scanner. It also carries a CVE with no patch. CVE-2026-25865 in Punto Switcher only surfaced because our sensor watched it run.

    Post summary

    The sample is a clean binary that contains the unpatched CVE‑2026‑25865 in Punto Switcher, discovered solely by sensor monitoring.

    1001050
    12 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25865 Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the applic… https://www.cve.org/CVERecord?id=CVE-2026-25865

    Post summary

    The text provides a brief disclosure of CVE‑2026‑25865, describing an unquoted search path element flaw in Punto Switcher that permits local code execution.

    01010268
    57.6K followersView on X
  • Spektion@spektion
    General

    July's other two signals: Punto Switcher calls rundll32.exe with no path. CVE-2026-25865, CVSS 8.5, no patch. File scanners call the signed binary clean. OpenAI Codex shipped 555 releases this year. Firefox shipped 25.

    Post summary

    The post simply notes CVE-2026-25865 has a CVSS score of 8.5 and no patch is available, offering no further exploitation or mitigation details.

    1000038
    14 followersView on X
  • Spektion@spektion
    Disclosure

    A signed binary is not a safe one. Punto Switcher launches rundll32.exe without saying where to load it from. Drop a matching file beside it and the allowlisted app runs attacker code. Scanners call it clean. CVE-2026-25865, no patch. https://spektion.com/videos https://t.co/QkA0UxGNHk

    Post summary

    CVE‑2026‑25865 enables attackers to execute code by dropping a matching file next to a signed binary that launches rundll32.exe, with scanners missing the flaw and no patch available.

    0001046
    13 followersView on X
  • Spektion@spektion
    Disclosure

    Last week we said CVE scanning is signature AV in a new suit. Here's a real one we just disclosed. CVE-2026-25865: a signed Windows binary, nothing wrong on disk, RCE in a call it only makes at launch. No catalog-model scanner was going to flag it. We caught it at runtime.

    Post summary

    The author disclosed a newly identified CVE-2026-25865, a Windows binary Remote Code Execution flaw that triggers on launch and evades signature scanning.

    0001051
    12 followersView on X
  • Spektion@spektion
    Disclosure

    Spektion Research disclosure: CVE-2026-25865, an unquoted-path flaw in Punto Switcher that runs attacker-placed code at the user's privilege level. A file scanner would never flag it. The reason is the whole point.

    Post summary

    The post discloses CVE-2026-25865, an unquoted-path vulnerability in Punto Switcher that permits execution of attacker-controlled code at the user’s privilege level, but it does not provide a PoC, patch, or evidence of active exploitation.

    1000036
    12 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25865 Arbitrary Code Execution via Unquoted Search Path in Punt... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25865 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet references CVE‑2026‑25865 with a brief title and links to vulnerability details, but provides no PoC, exploit code, active exploitation, patch, or false‑positive claim.

    0000050
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25865 Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the applic… https://www.cve.org/CVERecord?id=CVE-2026-25865 ----- Traducción: CVE-2026-25865 Pun… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026‑25865, highlighting an unquoted search path element vulnerability in Punto Switcher that can lead to local code execution, without providing PoC, exploit, patch, or false‑positive information.

    0000028
    82 followersView on X
  • Spektion@spektion
    Disclosure

    How do you catch a vulnerability that is not on disk? Our Punto Switcher disclosure (CVE-2026-25865) is a signed binary with a flaw that only exists at runtime. David Westcott and Josh Skorich will break it down. Up on demand later this month: https://spektion.com/videos

    Post summary

    The text announces the disclosure of CVE-2026-25865 for Punto Switcher, noting a signed binary flaw that manifests only at runtime, with no PoC, patch, or exploitation details provided.

    0000042
    12 followersView on X

Explore more