Use-After-Free Vulnerability in Foxit PDF Editor and Reader
CVE-2026-91799

7.8HIGH

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
23 September 2026

What is CVE-2026-91799?

A use-after-free vulnerability in Foxit PDF Editor and Reader affects the handling of JavaScript array objects. When a specially crafted PDF is processed, the application may attempt to access memory that has already been freed. This flaw can lead to application crashes or even the execution of arbitrary code, posing a significant risk to users. It's essential for users of these products to apply the latest updates to mitigate potential security threats.

Affected Version(s)

Foxit PDF Editor Windows Versions 2026.2 and earlier

Foxit PDF Editor Windows Versions 14.0.7 and earlier

Foxit PDF Editor Windows Versions 13.2.6 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KPC of Cisco Talos
.