VYPR
High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026

CVE-2026-13126

CVE-2026-13126

Description

The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.

Affected products

3

Patches

Vulnerability mechanics

References

1

News mentions

1