VYPR
patchPublished Sep 23, 2026· 1 source

Foxit PDF Reader Vulnerable to Remote Code Execution via DeviceN Colorspace Flaw

A critical vulnerability in Foxit PDF Reader, identified as CVE-2026-91794, allows for remote code execution through an out-of-bounds write in its DeviceN Colorspace component.

Zero Day Initiative (ZDI) has disclosed a critical vulnerability, tracked as ZDI-26-730 and assigned CVE-2026-91794, affecting Foxit PDF Reader. This flaw permits remote attackers to execute arbitrary code on vulnerable installations of the popular PDF software. The vulnerability requires user interaction, meaning an attacker must trick a victim into opening a specially crafted malicious file or visiting a compromised webpage.

The specific technical weakness lies within the parsing of DeviceN colorspaces. Attackers can exploit this by triggering an out-of-bounds write, which occurs due to insufficient validation of user-supplied data. This memory corruption allows an attacker to overwrite adjacent memory regions, potentially leading to the execution of malicious code within the context of the current PDF Reader process.

With a CVSS score of 7.8, this vulnerability poses a significant risk to users who handle PDF documents. Foxit PDF Reader is widely used across various platforms, making a broad attack surface susceptible to exploitation. Successful exploitation could lead to a complete compromise of the user's system, depending on the privileges of the running process.

Foxit has acknowledged the vulnerability and has released an update to address the issue. Users are strongly advised to update their Foxit PDF Reader installations to the latest version as soon as possible to mitigate the risk. Further details on the security update can be found on Foxit's official security bulletins page.

The vulnerability was initially reported to Foxit on June 18, 2026. Following a coordinated disclosure process, ZDI published its advisory on September 23, 2026, with an update to the advisory on the same day. The research leading to the discovery of this flaw is credited to Liang Zhu.

This discovery highlights the ongoing challenges in securing complex document parsing software. PDF readers, in particular, are frequent targets due to their ubiquity and the rich feature sets they support, which often introduce complex parsing logic susceptible to memory-related vulnerabilities like out-of-bounds writes.

While the vulnerability requires user interaction, the ease with which malicious files can be distributed via email or compromised websites means that users remain at risk until they apply the necessary patches. Organizations should ensure their endpoint security solutions are up-to-date and that users are educated about the dangers of opening unsolicited attachments or clicking suspicious links.

This incident underscores the importance of timely patching and vendor responsiveness in addressing critical security flaws. Users of Foxit PDF Reader should prioritize applying the available security update to protect themselves from potential exploitation of CVE-2026-91794.

Synthesized by Vypr AI