Back

MEDIUM

Foxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability

Published Sep 23, 2026

Description

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Foxit
Published Sep 23, 2026
Updated Sep 23, 2026
Reserved Sep 15, 2026

CISA Vulnrichment

Updated Sep 23, 2026

NVD

Status Awaiting Analysis
Modified Sep 23, 2026

Red Hat

No data

ENISA EUVD

Assigner Foxit
Published Sep 23, 2026
Updated Sep 23, 2026

GitHub

No data