CVE-2026-5941: Foxit PDF Editor

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.

Affected products

  • Foxit PDF Editor: from 14.0.0, before 14.0.4 (fixed in 14.0.4); from 2023.0.0, before 2026.1.1 (fixed in 2026.1.1)
  • Foxit PDF Reader: before 2026.1.1 (fixed in 2026.1.1)

Published 2026-04-27. Last modified 2026-06-17.