OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-91816

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in Foxit PDF Editor/Reader affects its handling of PDF annotations, allowing reentrant annotation deletion via embedded JavaScript. This can lead to application crashes and potential exploitation, making it critical for organizations using this software to prioritize patching. Users of Foxit PDF Editor/Reader, particularly those in environments handling sensitive documents, should take immediate action to mitigate this risk.

CVE
CVE-2026-91816
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Java

Original NVD Description

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)