CVE-2026-18597General

LOWCVSS 8.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-06: 3Technical Details · 2026-08-06: 208-06
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Foxit ❗ CVE-2026-18597 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-foxit/ https://t.co/YPZ1uyJSGs

    Post summary

    The tweet alerts to a Foxit product vulnerability (CVE‑2026‑18597) and directs readers to an external source for more information, but provides no further technical, exploit, or remediation details.

    00000208
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-18597 The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vu… https://www.cve.org/CVERecord?id=CVE-2026-18597 ----- Traducción: CVE-2026-18597 La … http://infoflow.cloud`

    Post summary

    The passage briefly outlines a potential SSRF vulnerability in Foxit PDF Services API but provides no evidence of active exploitation, a PoC, or available fixes.

    0000034
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18597 The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vu… https://www.cve.org/CVERecord?id=CVE-2026-18597

    Post summary

    The post announces a newly disclosed SSRF flaw in Foxit PDF Services API’s PDF creation feature, which permits external file referencing and can potentially lead to SSRF attacks.

    000001.1K
    57.9K followersView on X

Explore more