ZDI-26-727: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Foxit PDF Reader annotation use-after-free CVE-2026-13128 enables remote code execution via a malicious file.
ZDI-26-727 discloses a use-after-free in Foxit PDF Reader annotation handling that allows remote code execution. Exploitation requires the target to open a malicious file or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-13128. The advisory does not say the flaw is being exploited.
- Use-after-free affects Foxit PDF Reader annotation handling.
- A malicious file or page is required for exploitation.
- CVE-2026-13128 is rated CVSS 7.8 by ZDI.
- Active exploitation is not mentioned.
Vulnerabilities mentionedAll →
- CVE-2026-131287.8<1%Embedding JavaScript within a PDF file will cause the page to be deletedpublished · foxit pdf editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13128 | Embedding JavaScript within a PDF file will cause the page to be deleted Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application. NVD description · AI analysis pending |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-13128.
This source does not provide full text. Read it at zerodayinitiative.com.