CVE-2026-5940
7.8Foxit Software Inc. · Foxit PDF Editor, Foxit PDF Reader
A use-after-free vulnerability in Foxit PDF Editor and Reader allows an attacker to trigger program crashes by accessing invalidated objects during UI refreshes.
Executive summary
A critical use-after-free vulnerability in Foxit PDF Editor and Reader may allow an attacker to cause application crashes or potentially lead to arbitrary code execution.
Vulnerability
This is a use-after-free vulnerability (CWE-416) triggered when a function initiates a UI refresh following the removal of comments via script. The vulnerability requires user interaction, specifically the opening of a malicious file, and can be triggered by an unauthenticated local user.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation could result in a total compromise of the application, leading to significant system instability and potential execution of unauthorized code on the host machine. This poses a serious threat to data integrity and system availability for organizations relying on Foxit software for document processing.
Remediation
Immediate Action: Update Foxit PDF Editor and Foxit PDF Reader to the latest patched versions provided by Foxit Software Inc. as outlined in their official security bulletins.
Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected behavior in PDF processing workflows that may indicate exploitation attempts.
Compensating Controls: Implement endpoint protection solutions and ensure that users operate with the principle of least privilege to limit the impact of potential application-level compromises.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the nature of use-after-free vulnerabilities, immediate patching is essential to prevent potential code execution scenarios. IT administrators should prioritize updating all instances of Foxit PDF Editor and Reader within their environment to the latest versions to eliminate the underlying memory management defect.
More Foxit Software Inc. CVEs
Sources
Originally found and disclosed by Anonymous working with TrendAI Zero Day Initiative, per the CVE Program record.