CVE-2026-91799High· 7.8▾ TwilightA use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in appl…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially crafted PDF may cause the application to access a released object during array processing, potentially resulting in application crashes or arbitrary code execution.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91818High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations
CVE-2026-91816High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations
CVE-2026-91809High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields
CVE-2026-91806High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields
CVE-2026-91805High· 7.8A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling
CVE-2026-91793High· 7.8When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data