OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-91805

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Foxit PDF Editor/Reader is vulnerable due to a use-after-free flaw in its PDF page-tree handling, which can be exploited by specially crafted PDFs to manipulate page structures during rendering. This can lead to memory corruption and application crashes, posing a significant risk to users. Organizations that utilize Foxit PDF products should prioritize patching this vulnerability to mitigate potential disruptions and security breaches.

CVE
CVE-2026-91805
Severity
HIGH
CVSS
7.8
EPSS
0.12%

Original NVD Description

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)