Junglewise Threat Intelligence

CVE-2026-13126: Foxit PDF Editor use after free in pop-up annotations

CVE-2026-13126 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are popular applications used to view and modify PDF documents. A security flaw allows a specially crafted PDF file to crash the application or potentially allow an attacker to take control of the computer if a user opens the malicious file. This could lead to the theft of sensitive data or the installation of unauthorized software.

Technical details

A Use-After-Free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor on Windows. The flaw is triggered when embedded JavaScript in a PDF deletes pages, rendering certain objects invalid. The application subsequently attempts a write operation on invalid pop-up annotations, leading to a memory corruption condition. An attacker can exploit this by enticing a user to open a malicious PDF, potentially achieving arbitrary code execution or information disclosure. The issue is resolved in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier, 2025.x, 2024.x, 2023.x
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched
  • 2026-07-08: advisory

References