logo

Foxit PDF Editor Vulnerabilities Let Attackers Execute Arbitrary JavaScript

ID: 03efd1a2-92b3-51b2-bd6b-303e9d81a358

STIX ID: report--03efd1a2-92b3-51b2-bd6b-303e9d81a358

Feed Name: cybersecurityNews.com

Threat Score
50/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Abinaya

...
...

Foxit addressed two moderate-severity XSS vulnerabilities (CVE-2026-1591 and CVE-2026-1592) in Foxit PDF Editor Cloud that allow arbitrary JavaScript execution via unsanitized layer names and attachment filenames; exploitation requires user interaction and authenticated access and could expose document contents and session data. Cloud instances are auto-updated, desktop users should apply the February 3, 2026 patches, and organizations are advised to review file-handling practices and restrict editing privileges as appropriate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.