CVE-2026-91790
When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional content attributes are malformed. As a result, the program may access an already-freed internal data structure, triggering a crash due to UAF.
- Published Sep 23, 2026
- CVSS 7.8 high
- 0.1% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- Multiple vulnerabilities in FoxIT products CERT-FR ·