CVE-2026-91794: Foxit Software Inc Foxit PDF Editor
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash and potentially lead to remote code execution.
Affected products
- Foxit Software Inc Foxit PDF Editor: up to and including 2026.2; up to and including 14.0.7; up to and including 13.2.6
- Foxit Software Inc Foxit PDF Reader: up to and including 2026.2
Published 2026-09-23. Last modified 2026-09-23.