CVE-2026-3777: Foxit PDF Editor

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted JavaScript and document structures can lead to a use-after-free condition and potentially allow arbitrary code execution.

Affected products

  • Foxit PDF Editor: up to and including 13.2.2.24014; from 14.0.0.33046, up to and including 14.0.2.33402; from 2023.1.0.15510, up to and including 2023.3.0.23028; from 2024.1.0.23997, up to and including 2024.4.1.27687; from 2025.1.0.27937, up to and including 2025.3.0.35737; up to and including 13.2.2.63349; …
  • Foxit PDF Reader: up to and including 2025.3.0.35737; up to and including 2025.3.0.69570

Published 2026-04-01. Last modified 2026-06-17.