ZDI-26-614: pdfforge PDF Architect PDF File Parsing OOB Write RCE Vulnerability
Executive Summary
A zero‑day vulnerability (ZDI-26-614) in pdfforge PDF Architect allows remote attackers to execute arbitrary code via an out‑of‑bounds write in PDF file parsing. Exploitation requires user interaction—visiting a malicious page or opening a crafted PDF file. The Zero Day Initiative rated the flaw with a CVSS score of 7.8.
Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-08-31T05:00:00+00:00 - Category: cves
Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
"A really great talent finds its happiness in execution."
— Johann Wolfgang von Goethe