CVE-2026-92176
largeOut-of-Bounds Read RCE in pdfforge PDF Architect App Object Parsing
CVE-2026-92176 is an out-of-bounds read (CWE-125) in how pdfforge PDF Architect handles App objects, caused by improper validation of user-supplied data that allows a read past the end of an allocated buffer. The flaw is triggered when a victim opens a malicious PDF file or visits a malicious page that feeds crafted content to the application, making user interaction a prerequisite. A successful exploit lets a remote attacker execute arbitrary code in the context of the current process, potentially gaining the privileges of the logged-in user. Anyone running an affected build of the Windows desktop PDF editor PDF Architect is exposed, particularly users who routinely open PDFs from untrusted sources. The bug was coordinated through Trend Micro's Zero Day Initiative (ZDI-CAN-28570); it is not in CISA's KEV catalog and no public proof-of-concept is known, so there is no evidence of in-the-wild exploitation.
What to do: Update PDF Architect to the newest release as soon as pdfforge ships a fix — confirm the patched version against the ZDI advisory, since the affected range was not stated in this data. Until then, warn users not to open unsolicited PDFs or follow links that auto-launch PDF Architect, and consider opening untrusted documents in a sandboxed or isolated viewer. IT teams should inventory endpoints for PDF Architect installs and prioritize patching machines used for handling external documents.
| pdfforge PDF Architect | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of App objects. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28570.
- Weakness
- CWE-125
- Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.