CVE-2026-57237: Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57237?
CVE-2026-57237 has a severity rating of 7.8, classified as high.
What is CVE-2026-57237?
CVE-2026-57237 is a use-after-free vulnerability in Foxit PDF Editor and Reader that can lead to remote code execution.
How do I fix CVE-2026-57237?
To fix CVE-2026-57237, users should update to the latest version of Foxit PDF Editor or Reader that addresses this vulnerability.
What applications are affected by CVE-2026-57237?
CVE-2026-57237 affects Foxit PDF Editor and Foxit PDF Reader.
What type of attack does CVE-2026-57237 enable?
CVE-2026-57237 enables a remote code execution attack when a specially crafted PDF with JavaScript is opened.