Zero-Day Vulnerability in PDF Architect Allows Remote Code Execution
A critical out-of-bounds write vulnerability in pdfforge PDF Architect's file parsing component enables remote code execution, requiring only user interaction with a malicious file or webpage.

Security researchers at Zero Day Initiative (ZDI) have disclosed a critical remote code execution vulnerability affecting pdfforge PDF Architect. The flaw, identified as ZDI-26-612, resides within the software's PDF file parsing component and allows attackers to execute arbitrary code on vulnerable systems.
The vulnerability stems from an improper validation of user-supplied data during the PDF parsing process. This oversight can lead to an out-of-bounds write, where the software attempts to write data beyond the allocated buffer. Successful exploitation of this flaw grants an attacker the ability to execute code within the context of the current user's process, potentially leading to a full system compromise.
Exploitation of ZDI-26-612 requires a degree of user interaction. Attackers must trick a victim into opening a specially crafted PDF file or visiting a malicious webpage that hosts such a file. This social engineering aspect is common for vulnerabilities found in document processing software, as it relies on users opening or interacting with potentially untrusted content.
The ZDI assigned a CVSS score of 7.8 to this vulnerability, classifying it as high severity. While not reaching the maximum critical score, a CVSS score of 7.8 indicates a significant risk to affected systems, especially given the potential for remote code execution.
The disclosure timeline indicates that ZDI first reported the vulnerability to pdfforge on January 27, 2026. After a period of confirmation and follow-up, the vendor acknowledged the report on March 23, 2026. Following further inquiries from ZDI, the vendor was notified of the intention to publish the advisory as a zero-day on July 13, 2026, leading to the coordinated public release on August 31, 2026.
As of the advisory's publication, there is no specific patch or update available from pdfforge to address this vulnerability. The ZDI advises that the only effective mitigation strategy is to restrict user interaction with the product, particularly by avoiding the opening of untrusted PDF files or visiting suspicious websites that might host them.
This vulnerability highlights the ongoing risks associated with complex file parsing components in widely used software. Attackers continue to target these areas, as flaws can lead to significant impact, including remote code execution. Users of pdfforge PDF Architect are strongly advised to remain vigilant and await vendor-provided security updates.
The Zero Day Initiative (ZDI) has published advisory ZDI-26-614 detailing a remote code execution vulnerability in pdfforge PDF Architect. This advisory updates previous reporting by providing the specific disclosure timeline, including the initial report date of February 19, 2026, and the coordinated public release on August 31, 2026. The vulnerability, discovered by Mat Powell of TrendAI, stems from an out-of-bounds write during PDF file parsing and carries a CVSS score of 7.8.
The Zero Day Initiative (ZDI) has published further details on the PDF Architect vulnerability, assigning it the identifier ZDI-26-613. The advisory includes a disclosure timeline indicating that ZDI first reported the vulnerability to pdfforge on February 12, 2026, with the vendor confirming receipt on March 23, 2026. ZDI published the advisory on August 31, 2026, following a standard disclosure process, and credited researcher soiax for the discovery.
This new advisory from Zero Day Initiative (ZDI-26-615) details a local privilege escalation vulnerability within pdfforge PDF Architect's activation-service Update Service. Unlike the previously reported remote code execution flaw, this vulnerability requires initial low-privileged access to exploit, allowing an attacker to gain SYSTEM privileges by leveraging an uncontrolled search path element that leads to an unsecured library load. The CVSS score for this specific privilege escalation flaw is 7.8.
The Zero Day Initiative (ZDI) has published advisory ZDI-26-611 detailing a remote code execution vulnerability in pdfforge PDF Architect, identified as an out-of-bounds read. This new advisory specifies that the vulnerability lies within the handling of App objects and requires user interaction, such as opening a crafted file or visiting a malicious webpage, for exploitation. The disclosure timeline indicates the vulnerability was reported to the vendor on November 27, 2025, with a coordinated public release on August 31, 2026.