CVE-2026-5940 Details
Description
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
A use-after-free vulnerability has been identified in Foxit PDF Reader and Foxit PDF Editor for Windows, as well as in Foxit PDF Editor for Mac. This vulnerability affects several different versions and stems from the improper handling of certain objects, which can lead to program crashes and potentially allow for arbitrary code execution. The issue arises when a function that triggers a user interface refresh is called after comments have been removed via a script, creating a scenario where an invalidated object is accessed, causing the application to crash.
Users can update to the latest versions of Foxit PDF Reader or Foxit PDF Editor. For Foxit PDF Reader, the updated version can be downloaded from the Foxit website or via the application's update feature. For Foxit PDF Editor, the latest version is also available on the Foxit website or through the application's update option.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | < 13.2.4 >= 14.0.0, < 14.0.4 >= 2023.0.0, < 2026.1.1 |
CPE
Remediation
| |
| foxit pdf reader | < 2026.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | New CVE Received | Foxit |