CVE-2026-16633Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-08); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-07: 1Mentions · 2026-08-08: 2Mentions · 2026-08-13: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-08: 208-0708-0808-13
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-071
Disclosure1
2026-08-082
Disclosure1General1
2026-08-131
Disclosure1
Full discourse4 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: High severity vulnerability in PDF.js, CVE-2026-16633 may allow attackers to compromise users through malicious PDF content. Advisory at: https://github.com/mozilla/pdf.js/security/advisories/GHSA-hq66-cqwq-w95j #Patch #Patch #Patch

    Post summary

    The text alerts that CVE-2026-16633 is a high‑severity flaw in PDF.js capable of allowing malicious PDFs to compromise users, and directs readers to a GitHub advisory for a patch.

    01000302
    7.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 ngx-extended-pdf-viewer, Arbitrary #JavaScript Execution (XSS), #CVE-2026-16633 (High) -DC-Aug2026-1477 https://dailycve.com/ngx-extended-pdf-viewer-arbitrary-javascript-execution-xss-cve-2026-16633-high-dc-aug2026-1477/

    Post summary

    The article announces a new high‑severity vulnerability (CVE-2026-16633) in ngx‑extended‑pdf‑viewer that allows arbitrary JavaScript execution (XSS).

    0001052
    226 followersView on X
  • DailyCVE@dailycve
    General

    🔴 PDFjs Code Injection Vulnerability - #CVE-2026-16633 (High) -DC-Aug2026-1464 https://dailycve.com/pdfjs-code-injection-vulnerability-cve-2026-16633-high-dc-aug2026-1464/

    Post summary

    The post announces a high‑severity PDFjs code injection vulnerability but provides no evidence of exploitation, patches, or PoC details.

    0000058
    226 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - PDF.js Arbitrary JS Execution via PDF Scripting (CVE-2026-16633) In pdfjs-dist (PDF.js), loading a malicious PDF with scripting enabled (default) and no CSP blocking script-src allows attacker-supplied PDF JavaScript to execute in the hosting origin when the PDF is opened, leading to full DOM access/session theft. Deployments with CSP disallowing script-src are not impacted. 👉Affected: pdfjs-dist (versions unknown)

    Post summary

    The post announces CVE-2026-16633 affecting PDF.js, where malicious PDFs can trigger arbitrary JavaScript execution in the host origin when scripting is enabled and CSP is absent. A workaround is to disallow script-src via CSP.

    0000098
    282 followersView on X

Explore more