ZDI discloses two Foxit PDF Reader out-of-bounds write RCE flaws (CVE-2026-91811, CVE-2026-91794)
ZDI published two Foxit PDF Reader out-of-bounds write vulnerabilities, each rated CVSS 7.8, that could allow remote code execution when a user opens a malicious file or visits a malicious page; neither is reported as exploited in the wild.
On 2026-09-23, ZDI published two advisories for out-of-bounds write vulnerabilities in Foxit PDF Reader, both capable of enabling remote code execution. ZDI-26-740 (CVE-2026-91811) affects PRC stream parsing, while ZDI-26-730 (CVE-2026-91794) affects DeviceN colorspace processing. In both cases, a remote attacker could execute arbitrary code on affected installations, but exploitation requires user interaction: the target must open a crafted file or visit a malicious page. ZDI assigned each issue a CVSS score of 7.8. Neither advisory reports exploitation in the wild.
- ZDI-26-740 (CVE-2026-91811) is an out-of-bounds write in Foxit PDF Reader PRC stream parsing that can allow remote code execution.
- ZDI-26-730 (CVE-2026-91794) is an out-of-bounds write in Foxit PDF Reader DeviceN colorspace handling that can allow remote code execution.
- Both vulnerabilities were rated CVSS 7.8 by ZDI.
- Both flaws require user interaction: opening a malicious file or visiting a malicious page.
- Neither advisory reports exploitation in the wild.
- Both advisories were published by ZDI on 2026-09-23.
Coverage timelineoldest first · each row is one article
- · 4d agoZDI-26-730: Foxit PDF Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI Published Advisories· 52
Foxit PDF Reader DeviceN out-of-bounds write can enable remote code execution after user interaction.
- · 4d agoZDI-26-740: Foxit PDF Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI Published Advisories· 58
ZDI disclosed a Foxit PDF Reader out-of-bounds write that can enable remote code execution.
Vulnerabilities in this storyAll →
- CVE-2026-917947.8—Out-of-bounds RCE in Foxit PDF Editor/Reader due to Malformed Color Space Datapublished · Foxit PDF Editor/Reader+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-91794+1 related CVE | Out-of-bounds RCE in Foxit PDF Editor/Reader due to Malformed Color Space Data This vulnerability is an out-of-bounds write in the PDF rendering process of Foxit PDF Editor/Reader caused by insufficient consistency and boundary validation of malformed color space data. It can trigger program crashes and may enable remote code execution, presenting a high risk to system integrity. An attacker could exploit this flaw to gain unauthorized access and perform malicious actions, potentially affecting users or devices with the affected product. Currently, there is no known public exploit, and the vulnerability has not yet been actively exploited. |