ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability

mediumVulnerabilityimportance 24CVE-2026-13128
AI summary · glm-5.3-flash

ZDI disclosed a use-after-free in Foxit PDF Reader (CVE-2026-13128) enabling remote code execution when a user opens a malicious file.

Zero Day Initiative advisory ZDI-26-602 describes a use-after-free flaw in Foxit PDF Reader's document object handling. Exploitation yields arbitrary code execution but requires the target to open a malicious page or file. ZDI assigned CVSS 7.8 and CVE-2026-13128. The advisory does not report active exploitation.

  • Use-after-free in Foxit PDF Reader document object handling allows RCE
  • User interaction required to trigger the flaw
  • Rated CVSS 7.8; tracked as CVE-2026-13128

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-13128
Embedding JavaScript within a PDF file will cause the page to be deleted.

Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.

NVD description · AI analysis pending
7.8<1%
  • foxit pdf editor
  • foxit pdf reader
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.

This source does not provide full text. Read it at zerodayinitiative.com.