High severity7.8NVD Advisory· Published Apr 1, 2026· Updated Apr 28, 2026
CVE-2026-3779
CVE-2026-3779
Description
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
- www.talosintelligence.com/vulnerability_reports/TALOS-2026-2365nvdThird Party AdvisoryExploit
News mentions
0No linked articles in our index yet.