CVE-2026-91811: Foxit Software Inc Foxit PDF Editor

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.

Affected products

  • Foxit Software Inc Foxit PDF Editor: up to and including 2026.2; up to and including 14.0.7; up to and including 13.2.6
  • Foxit Software Inc Foxit PDF Reader: up to and including 2026.2

Published 2026-09-23. Last modified 2026-09-23.