FoxitCVE-2026-91814
Foxit PDF: spoofing
Medium5.3CVE-2026-91814 · Published Sep 23, 2026
A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to appear validly signed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Editor Product | <= Versions 2026.2 and earlier | No fix yet |
| <= Versions 14.0.7 and earlier | No fix yet | |
| <= Versions 13.2.6 and earlier | No fix yet | |
| Foxit PDF Reader Product | <= Versions 2026.2 and earlier | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-347
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Sep 23 | Foxit PDF: use after free | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: use after free | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Sep 23 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: code execution | High7.9 | No fix yet |