ZDI discloses 10 Foxit PDF Reader vulnerabilities: six CVSS 7.8 remote code execution flaws and four CVSS 3.3 information disclosure use-after-frees
On 2026-09-23 Trend Micro's Zero Day Initiative published 10 advisories for Foxit PDF Reader: six remote code execution bugs rated CVSS 7.8 (one AcroForm out-of-bounds read and five use-after-frees in AcroForm and annotation handling) plus four CVSS 3.3 Doc…
Trend Micro's Zero Day Initiative published ten advisories on 2026-09-23 covering memory-safety flaws in Foxit PDF Reader. Six are rated CVSS 7.8 and allow remote code execution: ZDI-26-745 (CVE-2026-91817), an AcroForm out-of-bounds read; ZDI-26-744 (CVE-2026-91816), an AcroForm use-after-free; and four annotation use-after-frees — ZDI-26-722 (CVE-2026-91791), ZDI-26-724 (CVE-2026-91792), ZDI-26-727 (CVE-2026-13128) and ZDI-26-746 (CVE-2026-91818). The remaining four are Doc object use-after-frees rated CVSS 3.3 that can disclose sensitive information to a remote attacker: ZDI-26-725 (CVE-2026-57256), ZDI-26-726 (CVE-2026-13129), ZDI-26-729 (CVE-2026-91793) and ZDI-26-735 (CVE-2026-91806). Every advisory states that exploitation requires the victim to open a malicious file or visit a malicious page, meaning user interaction is needed in all cases. None of the ten advisories reports observed in-the-wild exploitation, and the notices do not state affected product versions or patch status. The reports are mutually consistent; no source disagreements were identified.
- Ten ZDI advisories for Foxit PDF Reader were published on 2026-09-23 by Trend Micro's Zero Day Initiative.
- Six flaws are rated CVSS 7.8 and classified as remote code execution: ZDI-26-745 / CVE-2026-91817 (AcroForm out-of-bounds read), ZDI-26-744 / CVE-2026-91816 (AcroForm use-after-free), ZDI-26-722 / CVE-2026-91791, ZDI-26-724 /…
- Four flaws are Doc object use-after-frees rated CVSS 3.3 that can disclose sensitive information: ZDI-26-725 / CVE-2026-57256, ZDI-26-726 / CVE-2026-13129, ZDI-26-729 / CVE-2026-91793 and ZDI-26-735 / CVE-2026-91806.
- All ten vulnerabilities require user interaction: the victim must open a malicious file or visit a malicious page.
- None of the ten advisories states that any of the flaws is being exploited in the wild.
- The advisories do not specify affected Foxit PDF Reader versions or remediation status.
Coverage timelineoldest first · each row is one article
- · 4d agoZDI-26-745: Foxit PDF Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability
ZDI Published Advisories· 52
Foxit PDF Reader AcroForm out-of-bounds read may allow remote code execution with user interaction.
- · 4d agoZDI-26-725: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
ZDI Published Advisories· 24
ZDI disclosed another Foxit PDF Reader use-after-free information-disclosure flaw, CVE-2026-57256.
- · 4d agoZDI-26-726: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
ZDI Published Advisories· 24
Vulnerabilities in this storyAll →
- CVE-2026-572567.8<1%When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form…published · foxit pdf editor+3 related
- CVE-2026-917917.8—Use-After-Free in Foxit PDF Editor/Reader via Crafted PDF JavaScriptpublished