CVE-2026-57259: Foxit PDF Editor

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.

Affected products

  • Foxit PDF Editor: up to and including 13.2.4.24048; from 14.0.0.33046, up to and including 14.0.4.33508; from 2023.1.0.15510, up to and including 2023.3.0.23028; from 2024.1.0.23997, up to and including 2024.4.1.27687; from 2025.1.0.27937, up to and including 2025.3.0.35737; from 2026.1.0.36452, up to and including 2026.1.1.36485
  • Foxit PDF Reader: up to and including 2026.1.1.36485

Published 2026-07-08. Last modified 2026-07-09.