Skip to content
Auto-CTI
Back to today
NEW MEDIUM B2

ZDI-26-598: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

B ZDI: Published Advisories · · CVE-2026-57242

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
7.8
EPSS
0%

Affected versions

pdf editor pdf reader

Key insight

Foxit PDF Reader is commonly used in manufacturing environments for document review; this RCE vulnerability with CVSS 7.8 requires patching but poses no geopolitical threat.

Description

A use-after-free vulnerability in Foxit PDF Reader enables remote code execution on affected installations. The flaw is triggered via processing AcroForm elements in malicious PDF files. Attackers require user interaction (opening a malicious file or visiting a malicious page). CVSS rating: 7.8. The CVE is documented in public advisories.

Risk score

51
cvss base
78.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
93.00
industry weight
1.10
freshness factor
0.50
exploitability factor
1.00
days old
16.00
vendor mismatch penalty
0.00

Path: operational

ESC