CVE-2026-91790High· 7.8▾ TwilightWhen rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due to UAF.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91818High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations
CVE-2026-91816High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations
CVE-2026-91809High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields
CVE-2026-91806High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields
CVE-2026-91805High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling
CVE-2026-91799High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects