All CosmicBytez Labs articles tagged #PDF, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-73041: SiYuan XSS via PDF Annotation Fields Grants Full Node.js Access
Critical CVSS 9.0 XSS in SiYuan's PDF annotation renderer allows script injection with full Node.js access on affected versions before v3.7.4.
- Security
CVE-2026-55229: Gotenberg SSRF via LibreOffice Bypasses Built-in Protections
A server-side request forgery vulnerability in Gotenberg's LibreOffice conversion endpoint allows crafted documents to silently probe internal network...
- News
Adobe Patches Actively Exploited Zero-Day That Lingered for Months
Adobe has patched an actively exploited zero-day in Acrobat and Reader that threat actors have been weaponizing via malicious PDF files since at least...
- News
Adobe Reader Zero-Day Exploited via Malicious PDFs Since
Threat actors have been exploiting an unpatched zero-day in Adobe Reader since at least November 2025, using specially crafted PDFs to fingerprint victims...
- News
Hackers Exploiting Acrobat Reader Zero-Day Flaw Since
Attackers have been silently exploiting an unpatched zero-day vulnerability in Adobe Acrobat Reader since at least November 2025, using malicious PDFs to...