CVE-2026-57260: Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)
Published Jul 8, 2026
·Updated
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and used it as a valid address, ultimately causing the application to crash.
Affected Software
17 affected components
Foxit Foxit PDF Editor/Reader
All of the following
Any of the following
Foxit PDF Editor<=13.2.4.24048
Foxit PDF Editor>=14.0.0.33046<=14.0.4.33508
Foxit PDF Editor>=2023.1.0.15510<=2023.3.0.23028
Foxit PDF Editor>=2024.1.0.23997<=2024.4.1.27687
Foxit PDF Editor>=2025.1.0.27937<=2025.3.0.35737
Foxit PDF Editor>=2026.1.0.36452<=2026.1.1.36485
Foxit PDF Reader<=2026.1.1.36485
Microsoft Windows
All of the following
Any of the following
Foxit PDF Editor<=13.2.3.63444
Foxit PDF Editor>=14.0.0.68868<=14.0.3.69295
Foxit PDF Editor>=2023.1.0.55583<=2023.3.0.63083
Foxit PDF Editor>=2024.1.0.63682<=2024.4.1.66479
Foxit PDF Editor>=2025.1.0.66692<=2025.3.0.69570
Foxit PDF Editor>=2026.1.0.70169<=2026.1.1.70276
Foxit PDF Reader<=2026.1.1.70276
Apple macOS
Event History
Jul 8, 2026
CVE Published
via MITRE·07:35 AM
Data Sourced
via MITRE·07:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57260?
CVE-2026-57260 has a high severity rating of 7.8.
2
How do I fix CVE-2026-57260?
To fix CVE-2026-57260, update Foxit PDF Editor and Foxit PDF Reader to the latest version provided by the vendor.
3
What applications are affected by CVE-2026-57260?
CVE-2026-57260 affects Foxit PDF Editor and Foxit PDF Reader.
4
What type of vulnerability is CVE-2026-57260?
CVE-2026-57260 is a type confusion vulnerability related to U3D Adobe Mesh Decompression.
5
What is the potential impact of CVE-2026-57260?
The potential impact of CVE-2026-57260 includes application crashes and potential exploitation through specially crafted PDF files.