CVE-2026-5943
7.8Foxit Software Inc. · Foxit PDF Editor, Foxit PDF Reader
A use-after-free vulnerability in Foxit PDF Editor and Reader allows for potential arbitrary code execution via manipulated document structures.
Executive summary
A critical use-after-free vulnerability in Foxit PDF software could lead to application crashes or arbitrary code execution when processing malicious PDF documents.
Vulnerability
This is a use-after-free vulnerability (CWE-416) where document structural anomalies cause invalid object references during script-driven modifications, resulting in access to an invalid pointer. The vulnerability requires user interaction, as an attacker must trick a user into opening a specially crafted PDF file.
Business impact
The CVSS score of 7.8 (High) reflects the potential for total loss of confidentiality, integrity, and availability if an attacker achieves code execution. Successful exploitation could lead to unauthorized system access, data theft, or the installation of malware on victim workstations, posing a significant risk to organizational endpoint security.
Remediation
Immediate Action: Consult the official Foxit Security Bulletins for the release of patches and apply all available security updates to the affected PDF Editor and Reader installations immediately.
Proactive Monitoring: Monitor endpoint logs for abnormal application termination events or unexpected process crashes that may indicate an exploitation attempt.
Compensating Controls: Deploy endpoint protection solutions that can detect and block the execution of malicious scripts embedded within PDF documents to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of the vulnerability, organizations should prioritize the deployment of vendor-supplied patches across all managed endpoints. Until updates are applied, users should be cautioned against opening suspicious or unsolicited PDF files, as the attack vector relies on user-initiated document processing.
More Foxit Software Inc. CVEs
Sources
Originally found and disclosed by Anonymous working with TrendAI Zero Day Initiative, per the CVE Program record.