Changeflow GovPing Data Privacy & Cybersecurity RealObjects PDFreactor Multiple Vulnerabilities
Priority review Notice Added Final

RealObjects PDFreactor Multiple Vulnerabilities

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 25th, 2026
Detected March 26th, 2026
Email

Summary

CERT-Bund has issued a security advisory regarding multiple vulnerabilities in RealObjects PDFreactor versions prior to 12.5. The vulnerabilities have a high CVSS base score of 8.8 and allow for remote attacks, potentially leading to code execution, denial-of-service, data manipulation, and information disclosure. Mitigation is available.

What changed

CERT-Bund has published a security advisory (WID-SEC-2026-0862) detailing multiple critical vulnerabilities in RealObjects PDFreactor, affecting versions prior to 12.5. These vulnerabilities, with a CVSS base score of 8.8, enable remote attackers to execute arbitrary code, cause denial-of-service conditions, manipulate data, bypass security measures, or disclose confidential information. The advisory indicates that mitigation measures are available.

Organizations using RealObjects PDFreactor, particularly on Linux, UNIX, or Windows operating systems, should immediately assess their exposure to these vulnerabilities. It is recommended to apply available mitigation strategies and update to a patched version of PDFreactor as soon as possible to prevent potential security breaches. The advisory highlights the high risk associated with these flaws, emphasizing the need for prompt action to protect systems and data.

What to do next

  1. Assess exposure to RealObjects PDFreactor vulnerabilities
  2. Apply available mitigation strategies
  3. Update to a patched version of PDFreactor

Source document (simplified)

[WID-SEC-2026-0862] RealObjects PDFreactor: Mehrere Schwachstellen CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 25.03.2026 Stand 26.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Linux
  • Sonstiges
  • UNIX
  • Windows

Produktbeschreibung

PDFreactor ist eine Software zur Konvertierung von HTML-Dokumenten in PDF.

Produkte

25.03.2026
- RealObjects PDFreactor <12.5

Angriff

Angriff

Ein Angreifer kann mehrere Schwachstellen in RealObjects PDFreactor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere, nicht näher spezifizierte Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 25th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-0862

Who this affects

Applies to
Manufacturers
Industry sector
3254 Pharmaceutical Manufacturing
Activity scope
Software Vulnerability Management Document Conversion
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Software Vulnerabilities Data Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.