Insecure DLL loading in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-57239
Published: July 8, 2026 / Updated: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to uncontrolled search path element in the Foxit update service when checking for updates. A remote attacker can place a malicious DLL file to escalate privileges.
User interaction is required to initiate the update check.
Affected software
Foxit PDF Reader for Windows
How to mitigate CVE-2026-57239
Foxit PDF Reader for Windows - update to 2026.1.2.36540