Foxit disclosed CVE-2026-18597, a high-severity blind server-side request forgery (SSRF) flaw in Foxit PDF Services API that affects versions released before 2026-07-27. The vulnerability resides in the product’s PDF creation feature, which can reference external files and be abused through URL redirection bypasses to make server-side requests. The issue is tracked as CWE-918 and carries a CVSS v3.1 vector of AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N, indicating a network-reachable flaw that can cause significant information disclosure with limited integrity impact.
Public advisories, including Foxit’s security bulletin and a Canadian Centre for Cyber Security notice, urged organizations using the API to review the vendor guidance and apply the available updates. The reported impact is primarily information disclosure, with the SSRF condition potentially allowing attackers with low privileges to coerce vulnerable servers into accessing unintended internal or external resources during PDF generation workflows.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On August 6, 2026, the Canadian Centre for Cyber Security published advisory AV26-784 covering the Foxit PDF Services API vulnerability. The advisory told users and administrators to review Foxit's bulletin and apply the necessary updates.
A new vulnerability entry, CVE-2026-18597, was recorded on August 6, 2026 for a blind SSRF affecting Foxit PDF Services API. The entry describes exploitation through the PDF creation feature and classifies the issue as CWE-918.
Foxit PDF Services API versions before 2026-07-27 are identified as affected by CVE-2026-18597, indicating the issue was addressed in version 2026-07-27 or later. The flaw is a blind SSRF in the PDF creation feature that can lead to information disclosure via URL redirection bypasses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecvefeed.io
Open sourcefoxit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.