High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-57237
CVE-2026-57237
Description
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
Affected products
3cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: <=13.2.4.24048
- (no CPE)
Patches
Vulnerability mechanics
References
1- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
News mentions
1- ZDI-26-600: Foxit PDF Reader Annotation Use-After-Free Information Disclosure VulnerabilityZero Day Initiative · Aug 24, 2026