Skip to content
Vulnerabilities

20 Remote Code Execution Vulnerabilities Patched in Foxit PDF Reader and Editor

Foxit has patched 20 remote code execution vulnerabilities in Foxit PDF Reader and Foxit PDF Editor, and users should update immediately. The fixes arrive in the July 8, 2026 security release and cover multiple Windows and macOS versions, with several flaws rated Important and capable of arbitrary c...

· Jul 09, 2026 · 3 min read · 👁 3 views
20 Remote Code Execution Vulnerabilities Patched in Foxit PDF Reader and Editor

Foxit has patched 20 remote code execution vulnerabilities in Foxit PDF Reader and Foxit PDF Editor, and users should update immediately.

The fixes arrive in the July 8, 2026 security release and cover multiple Windows and macOS versions, with several flaws rated Important and capable of arbitrary code execution.

The update addresses a broad set of memory corruption and parsing bugs, including use-after-free, out-of-bounds read and write, buffer copy errors, type confusion, and array index validation issues.

Many of the flaws can be triggered by specially crafted PDF files, including those containing embedded JavaScript, abnormal annotations, malformed page trees, corrupted signature fields, or deceptive XDP content.

Foxit also patched a local privilege escalation issue in the update mechanism, in which the service could load malicious DLLs or executables with elevated privileges during update checks.

That makes this release important not only for document-opening risks, but also for system-level exposure on affected machines.

Patches in Foxit PDF Reader and Editor

The most serious bugs can let an attacker run code remotely when a victim opens a malicious PDF, which is especially dangerous because PDF readers are common targets in phishing campaigns.

Some issues can also expose information, crash the application, or lead to privilege escalation, depending on the flaw and the file content used to trigger it.

Several of the vulnerabilities were assigned CVSS scores of 7.8. In contrast, the update-path privilege-escalation issue was scored 8.2, indicating that this is not a routine maintenance release.

CVE IDCWEVulnerability TypeImpact
CVE-2026-13126CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-13127CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-13128CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-13129CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57237CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57238CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57240CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57242CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57244CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57245CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57247CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57249CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57250CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57252CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57256CWE-416Use After FreeArbitrary/Remote Code Execution
CVE-2026-57246CWE-120Buffer Copy without Size CheckArbitrary Code Execution
CVE-2026-57248CWE-763Release of Invalid PointerArbitrary Code Execution
CVE-2026-57251CWE-129Improper Validation of Array IndexArbitrary Code Execution
CVE-2026-57254CWE-843Type ConfusionArbitrary Code Execution
CVE-2026-57260CWE-787Out-of-Bounds WriteArbitrary Code Execution

Foxit credited multiple researchers and security groups, including Trend Zero-Day Initiative, Cisco Talos, and others, for reporting the issues.

Foxit said the fixes are included in Foxit PDF Reader 2026.1.2 and Foxit PDF Editor 2026.1.2 for Windows, as well as updated Mac releases.

Older Reader and Editor builds across multiple product lines are listed as affected, including 2026.x, 2025.x, 2024.x, 2023.x, 14.x, and some 13.x builds, depending on the product and platform.

Foxit recommends updating through the in-app “Check for Update” option or by downloading the latest release from its website.

Because the bugs affect document parsing and JavaScript execution, the safest move is to patch before opening untrusted PDFs, especially those received via email or messaging apps.

This is the kind of update security teams should treat as urgent, because PDF readers sit directly on the path between attackers and users.

Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor ChecklistDownload Free AI SOC SLA Guide

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you