CVE-2026-91791

When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition involving JavaScript triggered by page-visibility events. This can cause the application to access a released page-view object while calculating annotation boundaries, resulting in an invalid memory read and application crash.

  • Published Sep 23, 2026
  • CVSS 7.8 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-91791 at the National Vulnerability Database