Foxit PDF Reader Vulnerable to Remote Code Execution via JPEG2000 Parsing Flaw
A memory corruption vulnerability in Foxit PDF Reader's JPEG2000 parsing allows remote code execution, assigned CVE-2026-91815.

A critical vulnerability has been identified in Foxit PDF Reader that allows for remote code execution. The flaw, detailed by the Zero Day Initiative (ZDI) as ZDI-26-743 and assigned CVE-2026-91815, resides within the software's handling of JPEG2000 image parsing.
The vulnerability stems from an improper validation of user-supplied data during the JPEG2000 parsing process. This oversight can lead to a memory corruption condition, which an attacker can exploit to execute arbitrary code within the context of the currently running Foxit PDF Reader process. The CVSS score for this vulnerability is rated at 7.8, indicating a high severity.
Exploitation of this vulnerability requires a degree of user interaction. Attackers must trick a user into opening a specially crafted malicious file or visiting a malicious webpage that embeds the compromised JPEG2000 image. Once the user interacts with the malicious content, the attacker can achieve code execution on the victim's system.
Foxit has acknowledged the vulnerability and has released an update to address the issue. Users of Foxit PDF Reader are strongly advised to apply the available patch as soon as possible to mitigate the risk of exploitation. Further details on the security bulletin and update can be found on Foxit's official support page.
The disclosure timeline indicates that the vulnerability was initially reported to the vendor on September 9, 2026, with a coordinated public release of the advisory on September 23, 2026. This timeline suggests a standard responsible disclosure process was followed.
This discovery adds to a growing list of vulnerabilities found in popular PDF readers and document processing software. Attackers frequently target these applications due to their widespread use and the complex parsing mechanisms involved, which often present opportunities for memory corruption and code execution flaws.
Users should remain vigilant and ensure their software is kept up-to-date. Employing security best practices, such as being cautious about opening unexpected attachments or clicking on suspicious links, remains crucial in preventing successful exploitation of such vulnerabilities.
This advisory details a separate directory traversal vulnerability in Foxit PDF Reader, distinct from the JPEG2000 parsing flaw. The new vulnerability, ZDI-26-733 (CVE-2026-91797), also allows for remote code execution but exploits a different mechanism within PDF portfolios and requires user interaction. Foxit has released an update to address this specific issue.