ZDI-26-741: Foxit PDF Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability
ZDI disclosed a FoxitUpdater certificate flaw that lets network-adjacent attackers run code after a user opens a malicious file.
ZDI-26-741 covers improper certificate validation in the FoxitUpdater component of Foxit PDF Reader, tracked as CVE-2026-91812. Network-adjacent attackers can execute arbitrary code, but the target must visit a malicious page or open a malicious file. ZDI assigned CVSS 7.1 and describes the impact as local privilege escalation. The advisory does not state that exploitation has been observed.
- CVE-2026-91812 is improper certificate validation in FoxitUpdater.
- Network-adjacent attackers can execute arbitrary code after user interaction.
- ZDI rated the issue CVSS 7.1; exploitation is not reported as observed.
Vulnerabilities mentionedAll →
- CVE-2026-918127.9—CVE-2026-91812 RCE in Foxit PDF Editor/Reader Update Mechanismpublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91812 | CVE-2026-91812 RCE in Foxit PDF Editor/Reader Update Mechanism A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, enabling arbitrary code execution with system privileges. The flaw is triggered through the update mechanism, and an attacker can achieve arbitrary code execution with system privileges. Affected products are Foxit PDF Editor/Reader. Exploitation status is currently in the wild, with no publicly known exploit. Do: Upgrade to the latest Foxit PDF Editor/Reader; enable certificate validation and integrity checks; monitor for CVE-2026-91812 and related advisories; verify deployment and configuration to prevent MTI and privilege escalation. |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-91812.
This source does not provide full text. Read it at zerodayinitiative.com.