CVE-2026-91816: Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Published Sep 23, 2026
·Updated
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
Exploitation requires user interaction and a PDF containing embedded JavaScript that triggers reentrant annotation deletion. The attack vector is local, and no privileges are required.
2
What is the potential impact if exploitation succeeds?
The vulnerability can cause an application crash and is rated as having high confidentiality, integrity, and availability impact. It may result in remote code execution in the affected application context.