UPDATED 08:00 EDT / FEBRUARY 18 2026

SECURITY

Modern PDF platforms are becoming high-risk attack surfaces

Modern PDF platforms can now function as full attack gateways rather than passive document viewers.

That’s according to a new report out today from artificial intelligence offensive security startup Novee Cyber Security Ltd., which identifies 16 exploitable vulnerabilities across two widely deployed PDF ecosystems, Foxit Software Inc. and Apryse Software Inc.

The report warns that PDF viewers are inheriting complex trust-boundary and dataflow risks typically associated with web applications. In several cases, opening a malicious document or visiting a crafted URL was sufficient to trigger code execution or data exposure without exploiting the browser or operating system. The vulnerabilities were found to span client-side viewers, embedded plugins and server-side PDF services.

The issues include document object model or DOM-based cross-site scripting through remote configuration and message handlers, server-side request forgery with data exfiltration channels, path traversal in backend collaboration services, and operating system command injection within PDF software development kit components.

Many of the weaknesses found by Novee’s researchers stem from how untrusted input from PDFs, web addresses or messages propagates across JavaScript engines, WebAssembly components, cross-origin iframes and backend rendering services without consistent validation.

Novee describes the attack chains as moving from an initial document, URL or embedded message through client-side state, iframe boundaries or postMessage handlers into high-risk sinks such as DOM rendering, internal network requests, filesystem access or operating system command execution.

In multiple scenarios, a single malicious PDF or crafted link was found to be enough to achieve exploitation under a trusted origin or back-end service, expanding the impact beyond document rendering to account takeover, persistent cross-user compromise or back-end remote code execution.

The research methodology used by the researchers centered on a multi-agent large language model system designed to generalize trust-boundary failures from a small set of confirmed vulnerabilities. One agent was found to enumerate high-impact sinks and traced backward to build source-to-sink chains. Another resolved dynamic code paths that static tools could not verify. A third converted confirmed chains into working proof-of-concept exploits.

The vulnerabilities detailed in the report were disclosed before publication following responsible a disclosure process, with remediation efforts conducted alongside affected vendors.

“As document platforms grow more powerful, they also become more dangerous when trust assumptions fail,” note the report’s authors. “The findings show how easily a familiar, widely trusted component can turn into a foothold for full system compromise. For attackers, PDFs are no longer just files. They are execution paths.”

Image: SiliconANGLE/Ideogram

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.