Insufficient Control Flow Management in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-5938
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper control flow management in automatic directory imports when handling tasks related to automatic directory imports. A remote attacker can trick the victim into opening a crafted document action chain to cause a denial of service.
User interaction is required to open a crafted document.
Affected software
Foxit PDF Reader for Windows
How to mitigate CVE-2026-5938
Foxit PDF Reader for Windows - update to 2026.1.1.36485