Improper Verification of Cryptographic Signature in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-91814
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause users to trust manipulated documents.
The vulnerability exists due to improper verification of cryptographic signatures in signature verification when handling signed documents. A remote attacker can provide a signed document with dynamically altered content to cause users to trust manipulated documents.
The issue occurs after the visibility of certain content is dynamically altered during incremental updates.
Affected software
Foxit PDF Reader for Windows
How to mitigate CVE-2026-91814
Foxit PDF Reader for Windows - update to 2026.2.1.39815