ZDI-26-746: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability

Executive Summary

A use‑after‑free flaw in Foxit PDF Reader’s annotation handling allows remote attackers to execute arbitrary code when a user opens a malicious PDF or visits a malicious page. The vulnerability requires user interaction and has a CVSS score of 7.8. It is identified as CVE‑2026‑91818 and was disclosed by the Zero Day Initiative.


Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-23T05:00:00+00:00 - Category: cves

Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91818.

"Into each life rain must fall but rain can be the giver of life and it is all in your attitude that makes rain produce sunshine."

— Byron Pulsifer
Source: Zero Day Initiative