Foxit has released critical security updates to address multiple use-after-free vulnerabilities that could lead to remote code execution (RCE) in its widely used PDF Reader and PDF Editor products.
The vulnerabilities, disclosed in Foxit’s July 8, 2026 security bulletin , affect Windows versions of Foxit PDF Reader and Foxit PDF Editor across multiple release branches, highlighting the continued risk posed by malformed PDF files weaponized with embedded JavaScript.
The patched flaws primarily stem from improper memory handling issues categorized under CWE-416 (Use-After-Free), where the application attempts to access freed or invalid memory objects.
Successful exploitation could allow attackers to execute arbitrary code in the context of the current user by tricking victims into opening specially crafted PDF documents.
These attack scenarios commonly rely on malicious JavaScript embedded within PDF files to trigger memory corruption conditions, ultimately leading to application crashes or controlled code execution.
Foxit confirmed that the vulnerabilities impact Foxit PDF Reader versions 2026.1.1.36485 and earlier, as well as a broad range of Foxit PDF Editor versions, including 2026.x, 2025.x, 2024.x, 2023.x, and legacy 14.x and 13.x branches.
The company has addressed these issues in Foxit PDF Reader 2026.1.2, Foxit PDF Editor 2026.1.2, and Foxit PDF Editor 14.0.5.
Vulnerability Details:
Below is a summary of various vulnerabilities addressed in this update:
Additionally, a potential issue was identified where the application could be vulnerable to a Local Privilege Escalation attack during update checks. This could allow attackers to execute malicious DLL files, since the Foxit update service runs user-controllable executables with elevated privileges.
Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
A targeted GodDamn ransomware incident shows the payload is not entirely new but the latest…
A large-scale exploitation campaign is actively weaponising known vulnerabilities across multiple content management systems, with…
A critical vulnerability has been discovered in HP Linux Imaging and Printing Software (HPLIP), which…
AssuranceAmerica, a U.S. provider of auto and renters insurance, has confirmed a significant data breach…
RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with…
A newly disclosed vulnerability pattern known as "GhostApproval" is exposing significant flaws in the trust…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
