ZDI-26-741: Foxit PDF Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability
ZDI disclosed a FoxitUpdater certificate flaw that lets network-adjacent attackers run code after a user opens a malicious file.
ZDI-26-741 covers improper certificate validation in the FoxitUpdater component of Foxit PDF Reader, tracked as CVE-2026-91812. Network-adjacent attackers can execute arbitrary code, but the target must visit a malicious page or open a malicious file. ZDI assigned CVSS 7.1 and describes the impact as local privilege escalation. The advisory does not state that exploitation has been observed.