CVE-2026-5939
EUVD-2026-2582527.04.2026, 12:16
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| foxit | pdf_editor | 14.0.0 ≤ 𝑥 < 14.0.4 |
| foxit | pdf_editor | 2023.0.0 ≤ 𝑥 < 2026.1.1 |
| foxit | pdf_reader | 𝑥 < 2026.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration