CVE-2026-5941

7.8

Foxit Software Inc. · Foxit PDF Editor, Foxit PDF Reader

Parsing logic flaws in Foxit PDF Editor and Reader allow for invalid memory writes and program crashes when processing malformed form field hierarchies.

Executive summary

A critical memory corruption vulnerability in Foxit PDF Editor and Reader allows for potential arbitrary code execution or system instability when processing malicious documents.

Vulnerability

The software contains a flaw in its parsing logic regarding form field hierarchies, which can be triggered by an attacker to cause invalid memory writes. This vulnerability requires user interaction, such as opening a specially crafted PDF file, and does not require prior authentication.

Business impact

The ability to trigger invalid memory writes poses a significant risk of arbitrary code execution, which could result in a full compromise of the local workstation or server. Given the CVSS score of 7.8, this vulnerability is classified as High, reflecting the potential for complete loss of confidentiality, integrity, and availability of the affected system.

Remediation

Immediate Action: Users should update their Foxit PDF software to the latest versions as soon as they are made available by the vendor to resolve the identified parsing flaws.

Proactive Monitoring: Security teams should monitor endpoint logs for unexpected crashes or error reports associated with the Foxit PDF application processes.

Compensating Controls: Deploy endpoint protection solutions to detect and block the execution of malicious PDF files and restrict the ability of PDF readers to execute arbitrary scripts or system commands.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a significant risk to organizational endpoints due to the potential for memory corruption and subsequent system compromise. Administrators must prioritize patching these versions immediately upon the release of security updates from Foxit to prevent potential exploitation.

More Foxit Software Inc. CVEs

Sources

Originally found and disclosed by Anonymous working with TrendAI Zero Day Initiative, per the CVE Program record.