OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-91792

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Foxit PDF Editor/Reader is vulnerable when handling specially crafted PDF files, which can trigger reentrant zoom and layout operations via JavaScript actions. This flaw can lead to a use-after-free condition, potentially causing application crashes and impacting user experience. Organizations using this software should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-91792
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Java

Original NVD Description

When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)