ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

Executive Summary

A zero‑day vulnerability (ZDI‑26‑613) in pdfforge PDF Architect allows remote attackers to execute arbitrary code via memory corruption during PDF file parsing. Exploitation requires user interaction, such as opening a malicious file or visiting a malicious page. The vulnerability has a CVSS score of 7.8.


Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-08-31T05:00:00+00:00 - Category: cves

Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

"Better than a thousand hollow words, is one word that brings peace."

— Buddha
Source: Zero Day Initiative