CVE-2025-64086: PDF-Xchange Editor

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Affected products

  • PDF-Xchange PDF-Xchange Editor: version 10.7.3.401 only

Published 2025-12-09. Last modified 2026-06-17.