OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-91793

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Foxit PDF Editor/Reader is vulnerable to a use-after-free condition triggered by opening specially crafted PDFs that contain malformed font data in annotation rich-text attributes. This vulnerability can lead to application crashes, potentially allowing for arbitrary code execution. Organizations using Foxit PDF products should prioritize patching this issue to mitigate the risk of exploitation.

CVE
CVE-2026-91793
Severity
HIGH
CVSS
7.8
EPSS
0.13%

Original NVD Description

When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)