ZDI-26-614: pdfforge PDF Architect PDF File Parsing OOB Write RCE Vulnerability

Executive Summary

A zero‑day vulnerability (ZDI-26-614) in pdfforge PDF Architect allows remote attackers to execute arbitrary code via an out‑of‑bounds write in PDF file parsing. Exploitation requires user interaction—visiting a malicious page or opening a crafted PDF file. The Zero Day Initiative rated the flaw with a CVSS score of 7.8.


Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-08-31T05:00:00+00:00 - Category: cves

Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

"A really great talent finds its happiness in execution."

— Johann Wolfgang von Goethe
Source: Zero Day Initiative