CVE-2020-26535: Foxitsoftware Foxit Reader
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to a write access violation (and read access violation).
Affected products
- Foxitsoftware Foxit Reader: before 10.1 (fixed in 10.1)
- Foxitsoftware Phantompdf: before 10.1 (fixed in 10.1)
Published 2020-10-02. Last modified 2026-06-17.