High severity7.8NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-57252
CVE-2026-57252
Description
When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, eventually leading to the application crashing.
Affected products
3cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*range: <=13.2.4.24048
- (no CPE)
Patches
Vulnerability mechanics
References
1- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
News mentions
1- ZDI-26-597: Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityZero Day Initiative · Aug 24, 2026