Redpacketsecurity CVE-2026-91941 and CVE-2026-92177: Critical Vulnerabilities in PDF Processing Tools
Article Content
- •CVE-2026-91941 allows denial of service via large PDF downloads in Crawl4AI.
- •CVE-2026-92177 enables remote code execution in pdfforge PDF Architect with user interaction.
- •Both vulnerabilities were published on September 15, 2026, and require immediate attention.
Two critical vulnerabilities were disclosed on September 15, 2026, affecting PDF processing tools. CVE-2026-91941 in Crawl4AI allows attackers to exploit uncontrolled resource consumption, leading to denial of service through large PDF downloads. This affects internet-facing APIs and multi-tenant platforms, posing a high operational risk. CVE-2026-92177 in pdfforge PDF Architect enables remote code execution via out-of-bounds write vulnerabilities, requiring user interaction to exploit. Both vulnerabilities lack active exploitation evidence but should be addressed promptly. The potential impact includes service disruption and unauthorized code execution on affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Crawl4AI and CVE-2026-91941 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…