Executive brief
Foxit PDF Editor and Reader are widely used document processing applications. An attacker positioned between a user and Foxit's update servers could intercept updates and inject malicious code, which would then execute with system-level privileges when the application installs the tampered update. This could lead to full system compromise and data theft.
Technical details
The vulnerability exists in the update mechanism's handling of SSL/TLS certificate validation and package integrity checks. An attacker on the network path (man-in-the-middle) can bypass these protections to serve malicious packages during the update process. No user interaction beyond initiating an update is required; the attack succeeds if the victim's system checks for or performs an automatic update over an insecure or compromised network.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed: CVE-2026-91812 disclosed
- 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released