Junglewise Threat Intelligence

CVE-2026-91809: Foxit PDF Reader use-after-free in form field handling

CVE-2026-91809 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Reader and PDF Editor are tools used to view and edit PDF documents. A flaw in how they process malformed PDF form fields can cause the application to crash when opening a specially crafted PDF file, potentially disrupting work and serving as a precursor to more serious attacks.

Technical details

A use-after-free vulnerability exists in the field-name traversal logic when processing malformed PDF form fields due to insufficient validation. An attacker can trigger a crash by delivering a malicious PDF file that an unsuspecting user opens locally, exploiting improper object lifecycle management. The vulnerability has been patched in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1 and later.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and earlier (2026.x); 2025.3.0.35737 and earlier (2025.x); 2024.4.1.27687 and earlier (2024.x); 2023.3.0.23028 and earlier (2023.x); 14.0.7.33751 and earlier (14.x); 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed: Public disclosure via NVD and Foxit security bulletin
  • 2026-09-23: patched: Fixes available in PDF Reader 2026.2.1 and PDF Editor 2026.2.1/14.0.8

References

Related threats