CVE-2026-5939: Foxit PDF Editor
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
Affected products
- Foxit PDF Editor: from 14.0.0, before 14.0.4 (fixed in 14.0.4); from 2023.0.0, before 2026.1.1 (fixed in 2026.1.1)
- Foxit PDF Reader: before 2026.1.1 (fixed in 2026.1.1)
Published 2026-04-27. Last modified 2026-06-17.