High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-13127
CVE-2026-13127
Description
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.
Affected products
3cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: <=13.2.4.24048
- (no CPE)
Patches
Vulnerability mechanics
References
1- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
News mentions
1- ZDI-26-603: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityZero Day Initiative · Aug 24, 2026