Foxit PDF Editor Vulnerabilities Let Attackers Execute Arbitrary JavaScript
ID: 03efd1a2-92b3-51b2-bd6b-303e9d81a358
STIX ID: report--03efd1a2-92b3-51b2-bd6b-303e9d81a358
Feed Name: cybersecurityNews.com
Foxit addressed two moderate-severity XSS vulnerabilities (CVE-2026-1591 and CVE-2026-1592) in Foxit PDF Editor Cloud that allow arbitrary JavaScript execution via unsanitized layer names and attachment filenames; exploitation requires user interaction and authenticated access and could expose document contents and session data. Cloud instances are auto-updated, desktop users should apply the February 3, 2026 patches, and organizations are advised to review file-handling practices and restrict editing privileges as appropriate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
