ZDI discloses two Foxit PDF Reader FoxitUpdater privilege escalation vulnerabilities (CVE-2026-91812, CVE-2026-91813)
ZDI published two advisories on 2026-09-23 for Foxit PDF Reader's FoxitUpdater component: an improper certificate validation flaw (CVE-2026-91812, CVSS 7.1) exploitable by network-adjacent attackers and a race condition (CVE-2026-91813, CVSS 7.8) enabling…
ZDI issued two advisories on 2026-09-23 covering separate vulnerabilities in the FoxitUpdater component of Foxit PDF Reader. ZDI-26-741 tracks CVE-2026-91812, an improper certificate validation flaw rated CVSS 7.1; a network-adjacent attacker can execute arbitrary code, but the target must first visit a malicious page or open a malicious file, and the impact is described as local privilege escalation. ZDI-26-742 tracks CVE-2026-91813, a race condition rated CVSS 7.8 that allows a local attacker who can already run low-privileged code on the target to escalate privileges. Neither advisory reports that exploitation has been observed in the wild.
- ZDI-26-741 / CVE-2026-91812: improper certificate validation in Foxit PDF Reader's FoxitUpdater component, rated CVSS 7.1.
- CVE-2026-91812 requires user interaction — the target must visit a malicious page or open a malicious file — before a network-adjacent attacker can execute arbitrary code; impact is local privilege escalation.
- ZDI-26-742 / CVE-2026-91813: race condition in the FoxitUpdater component, rated CVSS 7.8, resulting in local privilege escalation.
- CVE-2026-91813 requires the attacker to already have the ability to run low-privileged code on the target system.
- Both ZDI advisories were published 2026-09-23T05:00:00Z; neither reports in-the-wild exploitation.
Coverage timelineoldest first · each row is one article
- · 4d agoZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability
ZDI Published Advisories· 34
FoxitUpdater race condition CVE-2026-91813 lets a local low-privileged attacker escalate privileges on Foxit PDF Reader.
- · 4d agoZDI-26-741: Foxit PDF Reader FoxitUpdater Improper Certificate Validation Local Privilege Escalation Vulnerability
ZDI Published Advisories· 48
ZDI disclosed a FoxitUpdater certificate flaw that lets network-adjacent attackers run code after a user opens a malicious file.
Vulnerabilities in this storyAll →
- CVE-2026-918138.8—Local RCE in Foxit PDF Editor/Reader Update Mechanism 5.0+ (CVE-2026-91813)published · Foxit PDF Editor/Reader+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-91813+1 related CVE | Local RCE in Foxit PDF Editor/Reader Update Mechanism 5.0+ (CVE-2026-91813) A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and extraction due to insufficient file locking and integrity validation. This flaw enables local attackers to execute arbitrary code with elevated privileges. The affected product is Foxit PDF Editor/Reader, with no specific version range provided in the data. The exploitation status is currently unknown, as no public exploit has been disclosed. |