{"id":"CVE-2026-91814","title":"A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents","summary":"A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed c…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","cwe":["CWE-347"],"vendor":"Foxit Software Inc.","product":"Foxit PDF Editor","affected":["foxit_pdf_editor Versions 2026.2 and earlier","foxit_pdf_editor Versions 14.0.7 and earlier","foxit_pdf_editor Versions 13.2.6 and earlier","foxit_pdf_reader Versions 2026.2 and earlier"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:58:26.570","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91814","references":[{"url":"https://www.foxit.com/support/security-bulletins.html","label":"14984358-7092-470d-8f34-ade47a7658a2"}],"tags":["nvd","cve.org"],"epss":0.00172,"epssPercentile":0.06963,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-23T14:24:09.232400Z"},"ingestedAt":"2026-09-23T08:20:37.595Z","slug":"CVE-2026-91814","body":"## Overview\n\nA signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to appear validly signed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}