CVE-2026-18597: Foxit Software Inc Foxit PDF Services API

High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.

Affected products

Published 2026-08-06. Last modified 2026-08-26.