CVE-2026-2516Disclosure

MEDIUMCVSS 6.4 · MEDIUM

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4. This affects an unknown part in the library SHFOLDER.dll. Such manipulation leads to uncontrolled search path. The attack needs to be performed locally. Attacks of this nature are highly complex. It is indicated that the exploitability is difficult. The exploit is publicly available and might be used. Upgrading the affected component is recommended. The vendor explains: "[W]e have already addressed similar DLL search path vulnerability patterns through prior security updates. (...) Users are advised to use the latest version provided by the vendor."

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426CWE-427

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-15); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-15: 4Mentions · 2026-02-16: 1Mentions · 2026-02-20: 1PoC Mentioned / Linked · 2026-02-16: 1Active Exploitation · 2026-02-15: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-20: 102-1502-1602-20
Signal classification4 categories
Disclosure
233.3%
Exploit
233.3%
Active Exploitation
116.7%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-154
Active Exploitation1Disclosure1Exploit1General1
2026-02-161
Exploit1
2026-02-201
Disclosure1
Full discourse6 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting Unidocs ezPDF DRM Reader and ezPDF Reader (CVE-2026-2516) https://vuldb.com/?ctiid.346107

    Post summary

    The post indicates that CVE-2026-2516 is being targeted with elevated activity, implying potential active exploitation, but offers no technical or mitigation details.

    00010101
    2.1K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2516 (CVSS:7.3, HIGH) is Awaiting Analysis. A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4 on 32-bit. This affects an unkno..https://nvd.nist.gov/vuln/detail/CVE-2026-2516 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-2516, rated CVSS 7.3 (High), has been identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4 on 32‑bit systems. The vulnerability is currently awaiting analysis, with no PoC, exploit, patch, or evidence of active exploitation reported.

    0000029
    171 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Exploit

    🚨 HIGH severity alert: Unidocs ezPDF DRM Reader 2.0 & 3.0.0.4 (32-bit) vulnerable to uncontrolled search path (CVE-2026-2516). No patch, exploit public. Restrict access & monitor endpoints! 🔒 https://radar.offseq.com/threat/cve-2026-2516-uncontrolled-search-path-in-unidocs--c9... https://t.co/J8aIfU8pnC

    Post summary

    The tweet highlights a high‑severity CVE‑2026‑2516 with a publicly available exploit and no patch, urging users to restrict access and monitor endpoints.

    0000056
    265 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-2516 - Unidocs - ezPDF DRM Reader - https://www.redpacketsecurity.com/cve-alert-cve-2026-2516-unidocs-ezpdf-drm-reader/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2516 #unidocs #ezpdf-drm-reader

    Post summary

    The post announces CVE‑2026‑2516 for Unidocs ezPDF DRM Reader and links to a Red Packet Security alert, but provides no technical, exploit, or patch details.

    00000107
    3.5K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-2516 A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4 on 32-bit. This affects an unknown part in the library SHFOLDER.dll. Such manipu… https://www.cve.org/CVERecord?id=CVE-2026-2516

    Post summary

    A CVE was reported for Unidocs ezPDF DRM Reader involving an unknown part in SHFOLDER.dll; no PoC, exploit, patch, or active exploitation information is provided.

    00000342
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Exploit

    🚨 HIGH severity: Unidocs ezPDF DRM Reader 2.0 & 3.0.0.4 (32-bit) hit by an uncontrolled search path flaw. No patch, exploit public. Restrict local access & monitor endpoints! Details: https://radar.offseq.com/threat/cve-2026-2516-uncontrolled-search-path-in-unidocs--c9898b25 #... https://t.co/6sY0xT8qPs

    Post summary

    A high‑severity uncontrolled search path flaw in Unidocs ezPDF DRM Reader (CVE‑2026‑2516) is highlighted, noting the exploit is publicly available and no patch exists; the post urges restricting local access and monitoring endpoints as a mitigation.

    0000068
    265 followersView on X

Explore more