High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-13128
CVE-2026-13128
Description
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.
Affected products
3Patches
Vulnerability mechanics
References
1- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
News mentions
1- ZDI-26-602: Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityZero Day Initiative · Aug 24, 2026