Skip to content
Auto-CTI
Back to today
NEW MEDIUM B2

ZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

B ZDI: Published Advisories · · CVE-2026-13127

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
7.8
EPSS
0%

Affected versions

pdf editor pdf reader

Key insight

Critical security vulnerability in widely-used PDF reader enabling remote code execution upon user interaction; risk to technical documentation handling in manufacturing environments.

Description

A use-after-free vulnerability in Foxit PDF Reader enables remote code execution through annotation functionality. Exploitation requires user interaction (visiting a malicious page or opening a crafted file). Rated CVSS 7.8, the flaw poses significant risk to systems processing PDF documents in design workflows and technical documentation. No Known Exploited Vulnerabilities (KEV) status reported, but proof-of-concept or active exploitation may follow.

Risk score

51
cvss base
78.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
93.00
industry weight
1.10
freshness factor
0.50
exploitability factor
1.00
days old
16.00
vendor mismatch penalty
0.00

Path: operational

ESC