ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-598: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

mediumAdvisoryimportance 25CVE-2026-57242
AI summary · glm-5.3-flash

Foxit PDF Reader AcroForm use-after-free (CVE-2026-57242, CVSS 7.8) permits remote code execution through malicious PDF files or pages.

ZDI-26-598 details a use-after-free in the AcroForm component of Foxit PDF Reader, tracked as CVE-2026-57242 and rated CVSS 7.8. A remote attacker can execute arbitrary code if the target opens a malicious file or visits a malicious page. The advisory was published by the Zero Day Initiative on August 24, 2026.

  • Use-after-free in AcroForm handling allows arbitrary code execution
  • Requires user interaction with a malicious file or page
  • Tracked as CVE-2026-57242 with CVSS 7.8
VendorsFoxit
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-57242
The application opens the PDF, and JavaScript modifies the form.

The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, eventually leading to a crash.

NVD description · AI analysis pending
7.8<1%
  • foxit pdf editor
  • foxit pdf reader
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57242.

This source does not provide full text. Read it at zerodayinitiative.com.