CVE-2026-91818: Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published Sep 23, 2026
·Updated
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require local access or user involvement?
The CVSS vector indicates a local attack vector, no required privileges, and required user interaction. Remote network access alone is not indicated as sufficient for exploitation.