Security researchers reported multiple previously unknown weaknesses across the PDF ecosystem that can be exploited through crafted documents. Novee Security’s research into Foxit and Apryse PDF platforms described 13 vulnerability categories and 16 exploit paths, including critical XSS and OS command injection, with “one-click” scenarios where simply opening a document could trigger compromise and potentially enable account takeover or backend command execution.
Separately, a high-severity flaw in the widely used jsPDF library was disclosed as CVE-2026-25755 (CVSS 8.8), enabling PDF object injection via improper sanitization in the addJS method. By breaking out of the /JS (...) string (e.g., injecting ) >> /Action ...), an attacker can inject arbitrary PDF structures and actions such as /OpenAction, potentially triggering behavior even when JavaScript is disabled in the viewer and enabling document manipulation (e.g., altering /Annots or /Signatures) across different PDF viewers, including lightweight mobile/embedded parsers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
By 2026-02-23, guidance accompanying disclosure of CVE-2026-25755 recommended upgrading to jsPDF 4.1.0 or later and avoiding addJS with untrusted input until patched. Additional mitigation advice included strict input validation to prevent malicious PDF object injection.
Researcher ZeroXJacks disclosed a high-severity jsPDF vulnerability, tracked as CVE-2026-25755, affecting the addJS method and enabling PDF Object Injection through improper sanitization of user-controlled input. The researcher also demonstrated a proof of concept showing how crafted payloads could inject PDF structures and trigger actions such as /OpenAction.
On 2026-02-18, Novee Security published a study on Foxit and Apryse PDF systems identifying 13 vulnerability categories and 16 exploitation paths, including one-click attack scenarios, account takeover, and backend command execution risks. The researchers said they had coordinated disclosure with Foxit and Apryse and that CVEs were assigned to support patching.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.