OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-91804

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Foxit PDF Editor/Reader is vulnerable to a heap-based out-of-bounds write due to inadequate validation of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. This vulnerability can lead to memory corruption and application crashes, posing a significant risk to users handling potentially malicious PDFs. Organizations using Foxit products should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-91804
Severity
HIGH
CVSS
7.8
EPSS
0.12%

Original NVD Description

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.

Related CVEs

Other vulnerabilities affecting the same vendor(s)