ZDI discloses two Foxit PDF Reader directory traversal RCE flaws: ZDI-26-733 (CVE-2026-91797) and ZDI-26-734 (CVE-2026-91801)
The Zero Day Initiative published two Foxit PDF Reader directory traversal vulnerabilities on 2026-09-23 — one in Portfolio handling, one in RichMedia annotations — each rated CVSS 7.8 and capable of remote code execution after user interaction; neither is…
On 2026-09-23, the Zero Day Initiative published two advisories for directory traversal vulnerabilities in Foxit PDF Reader, both permitting remote code execution. ZDI-26-733 (CVE-2026-91797) affects the application's Portfolio handling, while ZDI-26-734 (CVE-2026-91801) affects RichMedia annotation handling. In each case, ZDI assigned a CVSS score of 7.8 and states that a remote attacker can execute arbitrary code on affected installations, but only after user interaction — specifically, the target must open a malicious file or visit a malicious page. Neither advisory reports exploitation in the wild. The advisories do not specify affected version numbers or patch availability.
- ZDI published advisories ZDI-26-733 and ZDI-26-734 on 2026-09-23 (timestamp 2026-09-23T05:00:00Z), both concerning Foxit PDF Reader.
- ZDI-26-733 is a directory traversal flaw in Foxit PDF Reader Portfolio handling, tracked as CVE-2026-91797.
- ZDI-26-734 is a directory traversal flaw in Foxit PDF Reader RichMedia annotation handling, tracked as CVE-2026-91801.
- Both vulnerabilities are rated CVSS 7.8 by ZDI.
- Both flaws allow a remote attacker to execute arbitrary code, but require user interaction: the target must open a malicious file or visit a malicious page.
- Neither advisory reports active or in-the-wild exploitation.
- The reports do not state affected Foxit PDF Reader versions or patch status.
- The two source reports are consistent; no factual disagreements were found.
Coverage timelineoldest first · each row is one article
- · 4d agoZDI-26-733: Foxit PDF Reader Portfolio Directory Traversal Remote Code Execution Vulnerability
ZDI Published Advisories· 48
ZDI disclosed a Foxit PDF Reader portfolio directory traversal that can lead to remote code execution.
- · 4d agoZDI-26-734: Foxit PDF Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability
ZDI Published Advisories· 52
Foxit PDF Reader RichMedia directory traversal can allow remote code execution after user interaction.
Vulnerabilities in this storyAll →
- CVE-2026-917977.8—Path Traversal in Foxit PDF Editor/Reader Vulnerabilitypublished · Foxit PDF Editor/Reader+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-91797+1 related CVE | Path Traversal in Foxit PDF Editor/Reader Vulnerability Foxit PDF Editor/Reader has a vulnerability where it fails to validate the directory traversal path in attached PDF filenames, allowing malicious files to be written to directories outside the expected secure area when the PDF is opened. This flaw is triggered by an attacker who can manipulate the filename to bypass path restrictions. An attacker can therefore gain unauthorized access to sensitive directories and potentially execute arbitrary commands or modify system files. The affected scope is limited to Foxit PDF Editor/Reader, and current public exploitation is not known. |