CVE-2026-1591Patch(foxit / pdf_editor_cloud)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch foxit pdf_editor_cloud systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed. This issue affects pdfonline.foxit.com: before 2026‑02‑03.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdf_editor_cloud

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-03); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
pdf_editor_cloud

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-02-03: 3Mentions · 2026-02-04: 3Mentions · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-04: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-04: 3Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-03: 3Technical Details · 2026-02-04: 3Technical Details · 2026-02-10: 102-0302-0402-10
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-033
Disclosure2Patch1
2026-02-043
Disclosure1Patch2
2026-02-101
Patch1
Full discourse7 posts
  • Ostorlab@OstorlabSec
    Disclosure

    🚨 CVE-2026-1591: Foxit PDF Editor Cloud Stored XSS Alert 🚨 Foxit Software A stored cross-site scripting vulnerability has been disclosed in Foxit PDF Editor Cloud, allowing attackers to inject persistent JavaScript via the file upload username field. The payload executes in the browsers of all users who later view affected file lists. A public proof of concept is available. Risk Severity: High. Public proof of concept available. Stored XSS in a cloud collaboration platform with broad user exposure. Impact: Persistent JavaScript execution in victim browsers. Session token theft and account takeover. Credential harvesting via phishing overlays. Unauthorized changes to document sharing and workflow approvals. Targeted attacks against business users with ongoing access. Root Cause: CWE-79, Improper Neutralization of Input During Web Page Generation. User supplied username metadata is stored during file upload and rendered without output encoding in shared file list views. Attackers can: Upload a file with a malicious JavaScript payload embedded in the username field. Persist the payload in upload metadata. Trigger execution when other users open shared document lists. Steal sessions, redirect users, or manipulate document permissions. Are You Affected? Vulnerable. All Foxit PDF Editor Cloud instances prior to the February 3, 2026 security patch. Fixed. Cloud service patched on 2026-02-03. Verify the admin panel shows a last update date of 2026-02-03 or later. Immediate Action Required: Verify your Foxit PDF Editor Cloud instance is fully patched. Force global session invalidation and require user reauthentication. Audit historical uploads for suspicious username values containing script or HTML payloads. Monitor logs for abnormal uploads and unexpected outbound browser requests. Stored XSS in collaboration tools turns one upload into a mass compromise. Patch and invalidate sessions immediately. 🛡️ #ostorlabCVE

    Post summary

    Foxit PDF Editor Cloud has a disclosed stored XSS vulnerability (CVE‑2026‑1591) with a public PoC, high severity, and a patch available as of 2026‑02‑03.

    00020123
    582 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Foxit PDF Editor Cloud の脆弱性 CVE-2026-1591/1592 が FIX:入力サニタイズ不備と XSS の恐れ https://iototsecnews.jp/2026/02/03/foxit-pdf-editor-vulnerabilities-let-attackers-execute-arbitrary-javascript/ この問題の原因は、PDF 内の “レイヤー名” や “添付ファイル名”といった、ユーザーが自由に書き換えられる情報を表示する際に、その中に含まれる悪意のプログラム (JavaScript) を無効化する処理 (サニタイズやエスケープ) が欠落していたことにあります。具体的には、攻撃者が特殊な名前 (例:<script>alert(1)</script> など) を付けたレイヤーや添付ファイルを含む PDF を作成し、それを被害者に開かせます。そのレイヤー・パネルや添付ファイル・リストをユーザーが表示するときに、名前として埋め込まれていたコードが、”文字” としてではなく “命令” としてブラウザ内で実行されてしまいます。これがクロスサイト・スクリプティング (XSS) と呼ばれる脆弱性の正体です。ご利用のチームは、ご注意ください。 #CVE20261591 #CVE20261592 #Foxit #PDFEditor

    Post summary

    Foxit PDF Editor Cloud has released a fix for CVE-2026-1591 and 1592, which were XSS vulnerabilities caused by missing sanitization of layer and attachment names.

    01000166
    483 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Foxit patches multiple XSS vulnerabilities (CVE-2026-1591, CVE-2026-1592, CVE-2025-66523) in PDF Editor Cloud and eSign, fixing input validation flaws that risk arbitrary JavaScript execution. #FoxitUpdates #XSSFix #USA https://ift.tt/rbZ2pR0

    Post summary

    Foxit announced patches for several XSS CVEs, fixing input validation flaws that could lead to arbitrary JavaScript execution.

    00010132
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1591 Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload fil… https://www.cve.org/CVERecord?id=CVE-2026-1591

    Post summary

    The post briefly describes a stored XSS vulnerability in Foxit PDF Editor Cloud’s file upload feature, noting a malicious username injection, but offers no PoC, exploit code, or patch details.

    00010272
    56.5K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Foxit PDF Editor Cloud users, update now! Critical XSS vulnerabilities (CVE-2026-1591, CVE-2026-1592) patched to prevent arbitrary JavaScript execution. https://thedailytechfeed.com/foxit-pdf-editor-patches-critical-vulnerabilities-allowing-arbitrary-javascript-execution/ #Security #Patch #Vulnerability #JavaScript #Update #Software #Threat #CVE #Cloud #Editor #Protection #Code #Exploit #Browser #Attack #Hacking #Tech #Safety #Digital #Web

    Post summary

    Foxit released patches for CVE‑2026‑1591 and CVE‑2026‑1592, fixing critical XSS flaws that enabled arbitrary JavaScript execution in its PDF Editor Cloud.

    0000066
    238 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Foxit patches XSS flaws in PDF Editor Cloud & eSign enabling arbitrary JavaScript execution Foxit fixed multiple moderate-severity XSS vulnerabilities (CVE-2026-1591 / CVE-2026-1592 in PDF Editor Cloud; CVE-2025-66523 in eSign) that let authenticated attackers inject script via attachment/layer fields or crafted URL parameters, risking session theft, data exposure, and malicious redirects. Update/ensure patched versions are deployed to eliminate this browser-context execution path. 🎯 Target: Global/Enterprise Productivity #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/foxit-pdf-editor-vulnerability/

    Post summary

    Foxit has released patches for moderate‑severity XSS flaws in its PDF Editor Cloud and eSign, urging users to update to prevent arbitrary JavaScript execution.

    0000049
    192 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1591 Stored XSS Vulnerability in Foxit PDF Editor Cloud via Mal... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1591 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-1591 as a stored XSS vulnerability in Foxit PDF Editor Cloud, linking to a vulnerability detail page, but contains no PoC, exploit code, active exploitation claims, or remediation information.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfoxitpdf_editor_cloud---

Explore more