CVE-2026-5939 Details
Description
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
A use-after-free vulnerability has been identified in Foxit PDF Reader and Foxit PDF Editor. This vulnerability arises when the application processes certain XFA PDFs, leading to a crash and potentially allowing arbitrary code execution. The issue is caused by the application accessing invalid objects or pointers that have been deleted without proper validation, during the calculation event processing of the crafted XFA PDF.
Users can update to Foxit PDF Reader 2026.1.1 or Foxit PDF Editor 2026.1.1/14.0.4. Instructions for updating are available on the Foxit website. For Mac users, Foxit PDF Editor and Foxit PDF Reader have also been released in versions 2026.1, which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | >= 14.0.0, < 14.0.4 >= 2023.0.0, < 2026.1.1 |
CPE
Remediation
| |
| foxit pdf reader | < 2026.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | New CVE Received | Foxit |