ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-595: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

mediumVulnerabilityimportance 30CVE-2026-57254
AI summary · glm-5.3-flash

Foxit PDF Reader has a use-after-free vulnerability (CVE-2026-57254, CVSS 7.8) allowing remote code execution when a user opens a malicious file or page.

ZDI-26-595 describes a use-after-free vulnerability in the annotation feature of Foxit PDF Reader, tracked as CVE-2026-57254 with a CVSS score of 7.8. Successful exploitation allows remote attackers to execute arbitrary code, but requires user interaction such as visiting a malicious page or opening a malicious file. The advisory does not mention any exploitation in the wild.

  • Use-after-free in annotation handling enables arbitrary remote code execution
  • CVSS 7.8; user interaction is required for exploitation
  • CVE-2026-57254; no in-the-wild exploitation reported
VendorsFoxit
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-57254
There is an abnormal annotation within the PDF that is referenced by other objects.

There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.

NVD description · AI analysis pending
7.8<1%
  • foxit pdf editor
  • foxit pdf reader
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-57254.

This source does not provide full text. Read it at zerodayinitiative.com.