ZDI-26-746: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
A second Foxit PDF Reader annotation use-after-free can allow remote code execution with user interaction (CVE-2026-91818).
ZDI-26-746 covers another annotation use-after-free in Foxit PDF Reader that allows remote code execution if a user opens a malicious file or visits a malicious page. ZDI rated it CVSS 7.8 and assigned CVE-2026-91818. The published advisory does not describe observed exploitation.
- Separate annotation use-after-free can yield remote code execution.
- Exploitation needs the user to open a file or visit a page.
- CVSS 7.8 and CVE-2026-91818 are assigned by ZDI.
- The advisory does not state in-the-wild exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-918187.8—Use-After-Free in Foxit PDF Editor/Reader Annotations (CVE-2026-91818)published · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91818 | Use-After-Free in Foxit PDF Editor/Reader Annotations (CVE-2026-91818) This vulnerability is a use-after-free issue in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. The flaw occurs when reentrant page-event processing during annotation enumeration releases the associated page object, which is subsequently accessed, leading to an application crash. Attackers could potentially exploit this flaw to gain unauthorized access or data disclosure. The affected products are Foxit PDF Editor/Reader. Exploitation status is unknown as no public exploit is known. Do: Upgrade to the latest version of Foxit PDF Editor/Reader to patch the use-after-free vulnerability. Implement proper memory management and re-check page objects during annotation enumeration to prevent crashes. Monitor for potential re-exploitation and maintain security updates to reduce risk. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91818.
This source does not provide full text. Read it at zerodayinitiative.com.