Foxit has released critical security updates to address multiple use-after-free vulnerabilities that could lead to remote code execution (RCE) in its widely used PDF Reader and PDF Editor products.
The vulnerabilities, disclosed in Foxit’s July 8, 2026 security bulletin, affect Windows versions of Foxit PDF Reader and Foxit PDF Editor across multiple release branches, highlighting the continued risk posed by malformed PDF files weaponized with embedded JavaScript.
Foxit Patches Multiple Use-After-Free Flaws
The patched flaws primarily stem from improper memory handling issues categorized under CWE-416 (Use-After-Free), where the application attempts to access freed or invalid memory objects.
Successful exploitation could allow attackers to execute arbitrary code in the context of the current user by tricking victims into opening specially crafted PDF documents.
These attack scenarios commonly rely on malicious JavaScript embedded within PDF files to trigger memory corruption conditions, ultimately leading to application crashes or controlled code execution.
Foxit confirmed that the vulnerabilities impact Foxit PDF Reader versions 2026.1.1.36485 and earlier, as well as a broad range of Foxit PDF Editor versions, including 2026.x, 2025.x, 2024.x, 2023.x, and legacy 14.x and 13.x branches.
The company has addressed these issues in Foxit PDF Reader 2026.1.2, Foxit PDF Editor 2026.1.2, and Foxit PDF Editor 14.0.5.
Vulnerability Details:
Below is a summary of various vulnerabilities addressed in this update:
| CVE ID | Category (CWE) | Impact | Severity | CVSS 3.0 Score | Acknowledgement |
|---|---|---|---|---|---|
| CVE-2026-13126 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Anonymous working with TrendAI Zero Day Initiative |
| CVE-2026-13127 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Anonymous working with TrendAI Zero Day Initiative |
| CVE-2026-13128 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Anonymous working with TrendAI Zero Day Initiative |
| CVE-2026-13129 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Anonymous working with TrendAI Zero Day Initiative |
| CVE-2026-57237 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Anonymous working with TrendAI Zero Day Initiative |
| CVE-2026-57238 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Anonymous working with TrendAI Zero Day Initiative |
| CVE-2026-57240 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57242 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57244 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57245 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57247 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57249 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57250 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57252 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Anonymous working with TrendAI Zero Day Initiative |
| CVE-2026-57256 | Use After Free (CWE-416) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | KPC of Cisco Talos |
| CVE-2026-57239 | Uncontrolled Search Path Element (CWE-427) | Local Privilege Escalation | Important | 8.2: AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N | Luke Paris (@Paradoxis) |
| CVE-2026-57246 | Buffer Copy without Checking Size of Input (CWE-120) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57248 | Release of Invalid Pointer or Reference (CWE-763) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57251 | Improper Validation of Array Index (CWE-129) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57254 | Type Confusion (CWE-843) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | XuPeng |
| CVE-2026-57260 | Out-of-Bounds Write (CWE-787) | Potential Arbitrary Code Execution | Important | 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | Liang Zhu |
Additionally, a potential issue was identified where the application could be vulnerable to a Local Privilege Escalation attack during update checks. This could allow attackers to execute malicious DLL files, since the Foxit update service runs user-controllable executables with elevated privileges.
Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN





