CVE-2026-57256: Foxit PDF Editor
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.
Affected products
- Foxit PDF Editor: up to and including 13.2.4.24048; from 14.0.0.33046, up to and including 14.0.4.33508; from 2023.1.0.15510, up to and including 2023.3.0.23028; from 2024.1.0.23997, up to and including 2024.4.1.27687; from 2025.1.0.27937, up to and including 2025.3.0.35737; from 2026.1.0.36452, up to and including 2026.1.1.36485
- Foxit PDF Reader: up to and including 2026.1.1.36485
Published 2026-07-08. Last modified 2026-07-09.