SB2026092343 - Multiple vulnerabilities in Foxit PDF Reader and Editror for Windows



SB2026092343 - Multiple vulnerabilities in Foxit PDF Reader and Editror for Windows

Published: September 23, 2026

Security Bulletin ID SB2026092343
CSH Severity
High
Patch available
YES
Number of vulnerabilities 30
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 63% Medium 10% Low 27%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 30 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2026-91799)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


2) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-91814)

CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause users to trust manipulated documents.

The vulnerability exists due to improper verification of cryptographic signatures in signature verification when handling signed documents. A remote attacker can provide a signed document with dynamically altered content to cause users to trust manipulated documents.

The issue occurs after the visibility of certain content is dynamically altered during incremental updates.


3) Path traversal (CVE-ID: CVE-2026-91801)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in RichMedia annotation handling when processing embedded PDF resources. A remote attacker can trick the victim into opening a crafted document to execute arbitrary code.


4) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-91813)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a time-of-check time-of-use race condition in the update process when downloading and extracting update files. A local user can race update file operations to escalate privileges.


5) Improper Certificate Validation (CVE-ID: CVE-2026-91812)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 7.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code with elevated privileges.

The vulnerability exists due to improper certificate validation in the update process when validating a server certificate during an update. A remote attacker can present an improperly validated certificate during an update to execute arbitrary code with elevated privileges.


6) Insecure DLL loading (CVE-ID: CVE-2026-91803)

CWE-ID: CWE-427 - Uncontrolled Search Path Element

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to an uncontrolled search path element in the update process when performing high-privilege operations. A local user can place a dynamic-link library in a user-writable directory to escalate privileges.


7) Incorrect permission assignment for critical resource (CVE-ID: CVE-2026-91798)

CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to incorrect permission assignment for a critical resource in the update daemon when performing update operations. A local user can exploit insecure update daemon permissions to escalate privileges.


8) External Control of File Name or Path (CVE-ID: CVE-2026-91797)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to external control of file name or path in PDF portfolio attachment handling when processing embedded malicious file paths. A remote attacker can trick the victim into opening a crafted PDF portfolio to execute arbitrary code.

The application directly uses attachment filenames referenced by Filespec entries.


9) Protection mechanism failure (CVE-ID: CVE-2026-91796)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to protection mechanism failure in the JavaScript API when opening PDFs containing certain JavaScript code. A remote attacker can trick the victim into opening a crafted PDF to disclose information.

A crafted PDF can trigger external SMB authentication without security prompts.


10) Untrusted Pointer Dereference (CVE-ID: CVE-2026-91795)

CWE-ID: CWE-822 - Untrusted Pointer Dereference

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to untrusted pointer dereference in the FileOpen plugin when opening a PDF containing a malicious FOPN_foweb encryption filter. A remote attacker can trick the victim into opening a crafted PDF to execute arbitrary code.


11) Use-after-free (CVE-ID: CVE-2026-91818)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


12) Use-after-free (CVE-ID: CVE-2026-91816)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


13) Use-after-free (CVE-ID: CVE-2026-91809)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


14) Use-after-free (CVE-ID: CVE-2026-91806)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


15) Use-after-free (CVE-ID: CVE-2026-91805)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


16) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2026-91788)

CWE-ID: CWE-668 - Exposure of resource to wrong sphere

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to improper attribute authorization checks in the app.activeDocs JavaScript API when handling certain JavaScript actions. A remote attacker can trick the victim into opening a document containing crafted JavaScript actions to disclose information.

The API can return full document objects for open documents in the same process.


17) Use-after-free (CVE-ID: CVE-2026-91793)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


18) Use-after-free (CVE-ID: CVE-2026-91792)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


19) Use-after-free (CVE-ID: CVE-2026-91791)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


20) Use-after-free (CVE-ID: CVE-2026-91790)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in image, annotation, JavaScript array, page, or form-field objects when handling crafted document content. A remote attacker can trick the victim into opening a crafted document to execute arbitrary code.


21) Out-of-bounds read (CVE-ID: CVE-2026-91817)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an out-of-bounds read in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to disclose information.


22) Out-of-bounds write (CVE-ID: CVE-2026-91815)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


23) Out-of-bounds write (CVE-ID: CVE-2026-91811)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


24) Out-of-bounds read (CVE-ID: CVE-2026-91810)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an out-of-bounds read in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to disclose information.


25) Out-of-bounds read (CVE-ID: CVE-2026-91808)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an out-of-bounds read in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to disclose information.


26) Out-of-bounds read (CVE-ID: CVE-2026-91807)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an out-of-bounds read in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to disclose information.


27) Out-of-bounds write (CVE-ID: CVE-2026-91804)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


28) Out-of-bounds write (CVE-ID: CVE-2026-91802)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


29) Out-of-bounds write (CVE-ID: CVE-2026-91794)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an out-of-bounds write in the application when processing crafted content. A remote attacker can trick the victim into opening crafted content to execute arbitrary code.


30) Out-of-bounds write (CVE-ID: CVE-2026-91789)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in document and image processing when processing malformed U3D, PRC, AcroForm, image, or annotation data. A remote attacker can trick the victim into opening a crafted document to execute arbitrary code.


Remediation

Install update from vendor's website.