High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-13126
CVE-2026-13126
Description
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.
Affected products
3Patches
Vulnerability mechanics
References
1- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
News mentions
1- ZDI-26-604: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityZero Day Initiative · Aug 24, 2026