Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Zero-Day Flaws in PDF Software Risk Data Exposure

Critical Zero-Day Flaws in PDF Software Risk Data Exposure

Posted on February 18, 2026 By CWS

Significant security vulnerabilities have been uncovered in popular PDF platforms, posing a serious risk to enterprises globally. A total of 16 zero-day flaws, including critical OS Command Injection, DOM-based XSS, SSRF, and Path Traversal vulnerabilities, have been identified in Apryse WebViewer and Foxit PDF cloud services.

Details of the Discovered Vulnerabilities

The vulnerabilities were disclosed by Novee Security, which utilized a combination of AI and human expertise to identify these risks in widely used PDF platforms. The flawed systems affect millions of users, making it crucial for enterprises to address these security gaps immediately.

Both Apryse and Foxit were informed of these vulnerabilities under a responsible disclosure process, allowing them to release patches and mitigations before publicizing the issues.

Research Methodology and Vulnerability Impact

Apryse WebViewer’s architecture, which includes a React-based UI, a JavaScript/WebAssembly document engine, and a server-side SDK, was found to have significant trust boundary failures. These inadequacies in input validation were the root cause of the vulnerabilities.

Novee Security’s approach involved a blend of human intelligence and AI agents. The process included identifying vulnerability patterns and encoding these into agents designed to systematically explore and exploit these issues across the platform.

Particularly concerning is the Critical OS Command Injection vulnerability (CVSS 9.8) found in the Foxit PDF SDK for Web, allowing full remote code execution with a single POST request.

Specific Vulnerabilities and Recommendations

Among the vulnerabilities, an SSRF issue in Apryse WebViewer’s server-side iFrame rendering allows unauthorized content rendering, posing a network security risk. Apryse’s uiConfig parameter flaw also enables Critical DOM XSS through unsanitized JSON data.

Furthermore, a high-severity Path Traversal flaw in Foxit’s Collaboration Add-on permits unauthorized directory access. Multiple stored XSS vulnerabilities were also identified across Foxit’s platform.

Enterprises using Apryse WebViewer or Foxit PDF SDK for Web are urged to apply the available patches promptly. Additionally, conducting a thorough audit of their systems, particularly focusing on input validation protocols, is recommended to prevent exploitation of these vulnerabilities.

Implementing strict Content-Security-Policy and postMessage origin validation is also advised to enhance security across PDF components.

Stay updated with the latest cybersecurity developments by following us on Google News, LinkedIn, and X.

Cyber Security News Tags:AI security research, Apryse WebViewer, cyber attack prevention, cyber threats, Cybersecurity, data exfiltration, data protection, enterprise security, Foxit, OS command injection, PDF vulnerabilities, SSRF, XSS, zero-day

Post navigation

Previous Post: Critical Vulnerabilities in PDF Platforms Addressed by Foxit and Apryse
Next Post: Navigating Cybersecurity Amidst Constant Instability

Related Posts

Threat Actors Leverage Google Apps Script To Host Phishing Websites Threat Actors Leverage Google Apps Script To Host Phishing Websites Cyber Security News
Trend Micro Apex One Vulnerabilities: Critical Threats Uncovered Trend Micro Apex One Vulnerabilities: Critical Threats Uncovered Cyber Security News
Achieving Data Privacy Regulation Compliance in 2025 Frameworks Achieving Data Privacy Regulation Compliance in 2025 Frameworks Cyber Security News
Hackers Actively Attacking Linux SSH Servers to Deploy TinyProxy or Sing-box Proxy Tools Hackers Actively Attacking Linux SSH Servers to Deploy TinyProxy or Sing-box Proxy Tools Cyber Security News
EDR-Freeze Tool Technical Workings Along With Forensic Artifacts Revealed EDR-Freeze Tool Technical Workings Along With Forensic Artifacts Revealed Cyber Security News
Windows 11 24H2 Security Update Causes SSD/HDD Failures and Potential Data Corruption Windows 11 24H2 Security Update Causes SSD/HDD Failures and Potential Data Corruption Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trellix Data Breach Exposes Source Code to RansomHouse
  • Cyberattack Disrupts Canvas Platform as Finals Near
  • Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials
  • DarkMoon Launches AI-Driven Penetration Testing Platform
  • Cyberattacks Target Polish Water Facilities in 2025

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trellix Data Breach Exposes Source Code to RansomHouse
  • Cyberattack Disrupts Canvas Platform as Finals Near
  • Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials
  • DarkMoon Launches AI-Driven Penetration Testing Platform
  • Cyberattacks Target Polish Water Facilities in 2025

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark