Junglewise Threat Intelligence

CVE-2026-91804: Foxit PDF Editor and Reader heap overflow in Circle annotation rendering

CVE-2026-91804 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader are widely used applications for creating, editing, and viewing PDF documents in business and personal workflows. A flaw in how these products render Circle annotations in specially crafted PDF files can cause memory corruption and application crashes, potentially leading to code execution if an attacker crafts a malicious PDF and tricks a user into opening it.

Technical details

A heap-based out-of-bounds write vulnerability exists in the rendering of Circle annotations with malformed Cloudy appearance streams, stemming from insufficient validation of appearance geometry. The vulnerability is triggered when a user opens a specially crafted PDF file, requiring no authentication or special privileges; successful exploitation can result in memory corruption, application crash, or arbitrary code execution with the privileges of the user.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and earlier 2026.x; 2025.3.0.35737 and earlier 2025.x; 2024.4.1.27687 and earlier 2024.x; 2023.3.0.23028 and earlier 2023.x; 14.0.7.33751 and earlier 14.x; 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 and later

References

Related threats