Insecure DLL loading in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-57239

 

Insecure DLL loading in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-57239

Published: July 8, 2026 / Updated: August 6, 2026


Vulnerability identifier: #VU137066
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-57239
CWE-ID: CWE-427
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to uncontrolled search path element in the Foxit update service when checking for updates. A remote attacker can place a malicious DLL file to escalate privileges.

User interaction is required to initiate the update check.


Affected software

Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit PDF Reader for Windows

How to mitigate CVE-2026-57239

Install security update from vendor's website.

Foxit PDF Editor (formerly Foxit PhantomPDF) - addressed in versions 13.2.5.24109, 14.0.5.33580, 2026.1.2.36540, 2026.1.2.70304
Foxit PDF Reader for Windows - update to 2026.1.2.36540

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins