CVE-2026-91816
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.
- Published Sep 23, 2026
- CVSS 7.8 high
- 0.1% chance of exploitation in the next 30 days (EPSS)