ZDI-26-744: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed a Foxit PDF Reader AcroForm use-after-free enabling remote code execution via a malicious file.
The Zero Day Initiative published ZDI-26-744, a use-after-free in Foxit PDF Reader's AcroForm handling tracked as CVE-2026-91816. ZDI assigned CVSS 7.8 and says a remote attacker can execute arbitrary code if a user opens a malicious file or visits a malicious page. The advisory does not state that exploitation has been observed.
- CVE-2026-91816 is an AcroForm use-after-free in Foxit PDF Reader.
- ZDI rates it CVSS 7.8 and says it can lead to remote code execution.
- Exploitation requires the user to open a malicious file or visit a malicious page.
- The advisory does not report observed in-the-wild exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-918167.8—Use-after-free in Foxit PDF Editor/Reader with Reentrant Annotation Deletion Triggered by Embedded JavaScriptpublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91816 | Use-after-free in Foxit PDF Editor/Reader with Reentrant Annotation Deletion Triggered by Embedded JavaScript A use-after-free vulnerability exists in Foxit PDF Editor/Reader where reentrant annotation deletion caused by embedded JavaScript can lead to accessing a released annotation object, resulting in a crash. This flaw is triggered by specific reentrant annotation deletion scenarios involving embedded JavaScript. An attacker could potentially gain unauthorized access or other privileges through this vulnerability. The affected scope is limited to Foxit PDF Editor/Reader, though the exact affected version range is not specified. Do: Upgrade to the latest version of Foxit PDF Editor/Reader to mitigate the use-after-free vulnerability. Implement strict access controls and secure memory management to prevent reentrant annotation deletion. Monitor for CVE-2026-91816 and related patches to ensure full security mitigation. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91816.
This source does not provide full text. Read it at zerodayinitiative.com.