
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3776 is a null pointer dereference vulnerability in Foxit PDF Reader and Foxit PDF Editor that allows a crafted PDF document to crash the application, resulting in denial of service. The flaw affects Foxit PDF Reader versions up to and including 2025.3.0.35737/2025.3.0.69570, and Foxit PDF Editor versions up to 14.0.2, 13.2.2, 2025.3, 2024.4.1, and 2023.3.0 across multiple release branches. It was published on April 1, 2026, with a patch advisory from Foxit released around April 14, 2026. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Foxit Security Bulletins).
The root cause is a missing null or validity check before dereferencing the appearance (AP) stream object associated with stamp annotations in PDF documents (CWE-476: NULL Pointer Dereference). When a PDF file contains a stamp annotation that lacks its required AP entry, the application proceeds to access the associated object without first verifying its existence, causing a null pointer dereference. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted PDF file. No public proof-of-concept exploit code has been identified (GitHub Advisory, Foxit Security Bulletins).
Successful exploitation causes the affected Foxit PDF Reader or PDF Editor application to crash, resulting in a denial of service condition for the end user. There is no impact on confidentiality or data integrity, as the vulnerability only affects availability. The scope is limited to the application process itself, with no evidence of lateral movement potential or data exposure risk (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014–0.019%, placing it in a very low percentile for exploitation likelihood. Exploitation requires user interaction (opening a malicious PDF), which further limits the attack surface (GitHub Advisory).
/Subtype /Stamp) with the required AP (appearance) dictionary entry intentionally omitted or set to null.FoxitPDFReader.exe or FoxitPDFEditor.exe processes shortly after opening a PDF document, potentially with crash dump files generated in the application's crash reporting directory.Foxit has released patched versions addressing this vulnerability. Users should update Foxit PDF Editor to versions beyond 14.0.2, 13.2.2, 2025.3, 2024.4.1, and 2023.3.0, and update Foxit PDF Reader to versions beyond 2025.3. As interim mitigations, users should exercise caution when opening PDF files from untrusted or unknown sources, and organizations may consider implementing sandboxing for PDF processing or restricting PDF file handling to trusted sources. The official security bulletin is available at the Foxit support page (Foxit Security Bulletins, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."