CVE-2026-91807

6.1

Foxit Software · Foxit PDF Editor and Reader

A heap-based out-of-bounds read vulnerability in Foxit PDF Editor and Reader allows for an application crash via malformed image soft-mask data.

Executive summary

A heap-based out-of-bounds read vulnerability in Foxit PDF Editor and Reader may lead to service disruption through application crashes.

Vulnerability

This is a heap-based out-of-bounds read vulnerability triggered by insufficient validation of image soft-mask data during parsing. An unauthenticated attacker can trigger this condition if a victim opens a specially crafted malicious PDF file.

Business impact

While the CVSS score is 6.1, which categorizes this as a medium severity issue, the potential for application crashes poses a risk to business continuity. If critical workflows rely on these PDF tools for document processing, an attacker could induce a denial of service state, preventing users from accessing or generating necessary business documentation.

Remediation

Immediate Action: Update all installations of Foxit PDF Editor and Foxit PDF Reader to the most recent version provided by the vendor to ensure the parsing logic is patched.

Proactive Monitoring: Monitor system logs for repeated application crashes or unusual error reports associated with the PDF reader process, which may indicate attempts to exploit this vulnerability.

Compensating Controls: Implement endpoint protection policies that restrict users from opening untrusted or unsolicited PDF documents from unknown sources to reduce the likelihood of exposure.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

Organizations should prioritize the deployment of the latest security updates from Foxit Software to mitigate the risk of application instability. Given that this vulnerability requires user interaction, user awareness training regarding the handling of untrusted PDF files remains a recommended secondary defense strategy.

More Foxit Software CVEs all →

History

  1. Analyst report written

Sources

Originally found and disclosed by Anonymous working with TrendAI Zero Day Initiative, per the CVE Program record.