CVE-2026-91789

Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bounds write during pixel processing, potentially resulting in remote code execution.

  • Published Sep 23, 2026
  • CVSS 7.8 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-91789 at the National Vulnerability Database