Foxit has patched 20 remote code execution vulnerabilities in Foxit PDF Reader and Foxit PDF Editor, and users should update immediately.
The fixes arrive in the July 8, 2026 security release and cover multiple Windows and macOS versions, with several flaws rated Important and capable of arbitrary code execution.
The update addresses a broad set of memory corruption and parsing bugs, including use-after-free, out-of-bounds read and write, buffer copy errors, type confusion, and array index validation issues.
Many of the flaws can be triggered by specially crafted PDF files, including those containing embedded JavaScript, abnormal annotations, malformed page trees, corrupted signature fields, or deceptive XDP content.
Foxit also patched a local privilege escalation issue in the update mechanism, in which the service could load malicious DLLs or executables with elevated privileges during update checks.
That makes this release important not only for document-opening risks, but also for system-level exposure on affected machines.
Patches in Foxit PDF Reader and Editor
The most serious bugs can let an attacker run code remotely when a victim opens a malicious PDF, which is especially dangerous because PDF readers are common targets in phishing campaigns.
Some issues can also expose information, crash the application, or lead to privilege escalation, depending on the flaw and the file content used to trigger it.
Several of the vulnerabilities were assigned CVSS scores of 7.8. In contrast, the update-path privilege-escalation issue was scored 8.2, indicating that this is not a routine maintenance release.
| CVE ID | CWE | Vulnerability Type | Impact |
|---|---|---|---|
| CVE-2026-13126 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-13127 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-13128 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-13129 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57237 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57238 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57240 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57242 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57244 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57245 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57247 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57249 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57250 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57252 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57256 | CWE-416 | Use After Free | Arbitrary/Remote Code Execution |
| CVE-2026-57246 | CWE-120 | Buffer Copy without Size Check | Arbitrary Code Execution |
| CVE-2026-57248 | CWE-763 | Release of Invalid Pointer | Arbitrary Code Execution |
| CVE-2026-57251 | CWE-129 | Improper Validation of Array Index | Arbitrary Code Execution |
| CVE-2026-57254 | CWE-843 | Type Confusion | Arbitrary Code Execution |
| CVE-2026-57260 | CWE-787 | Out-of-Bounds Write | Arbitrary Code Execution |
Foxit credited multiple researchers and security groups, including Trend Zero-Day Initiative, Cisco Talos, and others, for reporting the issues.
Foxit said the fixes are included in Foxit PDF Reader 2026.1.2 and Foxit PDF Editor 2026.1.2 for Windows, as well as updated Mac releases.
Older Reader and Editor builds across multiple product lines are listed as affected, including 2026.x, 2025.x, 2024.x, 2023.x, 14.x, and some 13.x builds, depending on the product and platform.
Foxit recommends updating through the in-app “Check for Update” option or by downloading the latest release from its website.
Because the bugs affect document parsing and JavaScript execution, the safest move is to patch before opening untrusted PDFs, especially those received via email or messaging apps.
This is the kind of update security teams should treat as urgent, because PDF readers sit directly on the path between attackers and users.
Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide