Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities SecurityWeek

Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration

Novee researchers identified 16 vulnerabilities, including DOM XSS, SSRF, path traversal,
Read Full Article →

VULNERABILITIES Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration Novee researchers discovered 16 vulnerabilities in Foxit and Apryse PDF tools that could have been exploited via malicious documents or URLs. By Eduard Kovacs | February 18, 2026 (8:16 AM ET) Flipboard Reddit Whatsapp Email Researchers have identified more than a dozen vulnerabilities in popular PDF platforms from Foxit and Apryse, demonstrating how attackers could have exploited them for account takeover, data exfiltration, and other attacks. The vulnerabilities were discovered by researchers at penetration testing startup Novee, which emerged from stealth mode in January 2026 with over $51 million in funding. The findings were responsibly disclosed to Foxit and Apryse, and both vendors have patched the reported vulnerabilities. Novee’s research targeted Apryse WebViewer and Foxit PDF cloud services. Apryse WebViewer, formerly PDFTron, is a JavaScript-based document SDK and UI component library that enables developers to embed viewing, annotation, editing, and conversion features directly into web applications and browsers. ADVERTISEMENT. SCROLL TO CONTINUE READING. Foxit PDF cloud services, such as Foxit PDF Editor Cloud, are browser-based PDF solutions that provide a full-featured platform for viewing, creating, editing, annotating, organizing, converting, securing, exporting, and signing PDF documents and forms. Novee’s analysis — powered by specialized AI agents — led to the discovery of 16 vulnerabilities across Apryse and Foxit products. One critical and two high-severity vulnerabilities were found in Apryse products, and two high-severity and 11 medium-severity issues were identified in Foxit products. The list of flaws includes DOM XSS, SSRF, stored and reflected XSS, path traversal, and OS command injection vulnerabilities. Novee’s tests demonstrated that attackers could have exploited the security holes via specially crafted documents, URLs, or messages to execute arbitrary code or commands. “Several vulnerabilities were exploitable with a single request and affected trusted domains commonly embedded inside enterprise applications,” the security firm explained. The researchers showed that in scenarios where PDF viewers are embedded in authenticated applications an attacker could have leveraged the XSS flaws for account takeover. In addition, an attacker could have exploited the weaknesses to exfiltrate sensitive document or user data, manipulate documents, or achieve persistent compromise using payloads that survive page refreshes. “From a defender’s perspective, this means that a component long assumed to be low risk can quietly become a high-impact attack surface,” Novee said. SecurityWeek has reached out to both Foxit and Apryse for comment. Hongtao Huang, Group SDE, Product Security, Foxit, stated: “Foxit takes product security seriously and maintains an active responsible disclosure program for exactly this reason. When Novee Security Research identified these vulnerabilities and brought them to our attention, our security team engaged immediately. We worked collaboratively with Novee through the full remediation process and have published detailed updates through our Trust Center. We appreciate Novee’s professionalism and thoroughness throughout this process. This is responsible disclosure working exactly as it should. Foxit remains committed to ongoing transparency with the security research community and our customers.” Stan Kornacki, Vice President of IT and CISO, Apryse, commented: “The issues referenced in Novee’s upcoming research were responsibly reported and have been addressed through product updates, documentation improvements, and strengthened default configurations. We expect these types of issues to be infrequent, but when they appear, we address them promptly and thoroughly, keeping all parties informed throughout the process. Our vulnerability management processes are comprehensive — designed not just to remediate vulnerabilities but to assess potential data impact, test for unintended behavior, and ensure every release meets the high standard of code quality our customers deserve.” Related: APT-Grade PDFSider Malware Used by Ransomware Groups Related: CISA: Hackers Exploiting Vulnerability in Product of Taiwan Security Firm TeamT5 Related: Patch Tuesday: Adobe Fixes 44 Vulnerabilities in Creative Apps WRITTEN BY Eduard Kovacs Eduard Kovacs (@EduardKovacs) is the managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos Password Managers Vulnerable to Vault Compromise Under Malicious Server Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security Microsoft Warns of ClickFix Attack Abusing DNS Lookups Google Patches First Actively Exploited Chrome Zero-Day of 2026 Check Point Announces Trio of Acquisitions Amid Solid 2025 Earnings Beat BeyondTrust Vulnerability Targeted by Hackers Within 24 Hours of PoC Release Latest News CISA: Hackers Exploiting Vulnerability in Product of Taiwan Security Firm TeamT5 Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence Hackers Offer to Sell Millions of Eurail User Records Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems API Threats Grow in Scale as AI Expands the Blast Radius Man Linked to Phobos Ransomware Arrested in Poland TRENDING Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data Password Managers Vulnerable to Vault Compromise Under Malicious Server Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Google Patches First Actively Exploited Chrome Zero-Day of 2026 CISA Navigates DHS Shutdown With Reduced Staff Microsoft Warns of ClickFix Attack Abusing DNS Lookups Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’ Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit PEOPLE ON THE MOVE Robert Carvajal has been appointed as CISO of BayCare Health System. KnowBe4 announced the appointment of Kelly Morgan as Chief Customer Officer. CrowdStrike has named Jonathon Dixon as vice president and managing director for the JAPAC region. More People On The Move EXPERT INSIGHTS How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Email

Share this article