FoxitCVE-2026-18622
Foxit PDF Editor/Reader inconsistently alerts users
Medium4.7CVE-2026-18622 · Published Aug 13, 2026 · updated Sep 10, 2026
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Editor Product | <= Versions 2026.1.2 and earlier | No fix yet |
| <= Versions 14.0.5 and earlier | No fix yet | |
| <= Versions 13.2.5 and earlier | No fix yet | |
| Foxit PDF Reader Product | <= Versions 2026.1.2 and earlier | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-451
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 6 | Foxit PDF Services API: server-side request forgery | High8.5 | No fix yet |
| Jul 8 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Jul 8 | Foxit PDF: XML external entity | Medium6.5 | No fix yet |
| Jul 8 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: use after free | High7.8 | No fix yet |
| Jul 8 | Foxit PDF: improper array index validation | High7.8 | No fix yet |