CVE-2026-91796: Foxit PDF Editor
Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.
The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.
Affected products
- Foxit PDF Editor: up to and including 13.2.5.63482; from 14.0.0.33046, up to and including 14.0.7.33751; from 2023.1.0.15510, up to and including 2023.3.0.23028; from 2024.1.0.23997, up to and including 2024.4.1.27687; from 2025.1.0.27937, up to and including 2025.3.0.35737; from 2026.1.0.36452, up to and including 2026.2.0.39747
- Foxit PDF Reader: up to and including 2026.2.0.39747
Published 2026-09-23. Last modified 2026-10-08.