OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-91790

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Foxit PDF Editor/Reader is vulnerable due to improper validation of malformed optional content attributes in image objects, leading to a use-after-free (UAF) condition. This flaw can cause the application to crash, potentially allowing an attacker to exploit the vulnerability for further malicious actions. Organizations using Foxit PDF products should prioritize addressing this issue to mitigate risks associated with application stability and security.

CVE
CVE-2026-91790
Severity
HIGH
CVSS
7.8
EPSS
0.13%

Original NVD Description

When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due to UAF.

Related CVEs

Other vulnerabilities affecting the same vendor(s)