CVE-2026-3776 Details
Description
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference and crash the application, resulting in denial of service.
A null pointer dereference vulnerability has been identified in Foxit PDF Reader and Foxit PDF Editor. This issue arises when the application fails to validate the presence of required appearance (AP) data in stamp annotations before accessing related resources. As a result, a crafted PDF can trigger a null pointer dereference, causing the application to crash and leading to a denial-of-service condition. This vulnerability affects multiple versions of Foxit PDF Reader and Foxit PDF Editor on Windows and Mac platforms.
Users can update to Foxit PDF Reader or Foxit PDF Editor version 2026.1 or later. Instructions for updating are available on the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | <= 13.2.2.24014 >= 14.0.0.33046, <= 14.0.2.33402 >= 2023.1.0.15510, <= 2023.3.0.23028 >= 2024.1.0.23997, <= 2024.4.1.27687 >= 2025.1.0.27937, <= 2025.3.0.35737 <= 13.2.2.63349 >= 14.0.0.68868, <= 14.0.2.69164 >= 2023.1.0.55583, <= 2023.3.0.63083 >= 2024.1.0.63682, <= 2024.4.1.66479 >= 2025.1.0.66692, <= 2025.3.0.69570 |
CPE
Remediation
| |
| foxit pdf reader | <= 2025.3.0.35737 <= 2025.3.0.69570 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | Foxit |