CVE-2026-3776
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2026-3776 is a null pointer dereference vulnerability in Foxit PDF Reader and Foxit PDF Editor that allows a crafted PDF document to crash the application, resulting in denial of service. The flaw affects Foxit PDF Reader versions up to and including 2025.3.0.35737/2025.3.0.69570, and Foxit PDF Editor versions up to 14.0.2, 13.2.2, 2025.3, 2024.4.1, and 2023.3.0 across multiple release branches. It was published on April 1, 2026, with a patch advisory from Foxit released around April 14, 2026. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Foxit Security Bulletins).

Technical details

The root cause is a missing null or validity check before dereferencing the appearance (AP) stream object associated with stamp annotations in PDF documents (CWE-476: NULL Pointer Dereference). When a PDF file contains a stamp annotation that lacks its required AP entry, the application proceeds to access the associated object without first verifying its existence, causing a null pointer dereference. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted PDF file. No public proof-of-concept exploit code has been identified (GitHub Advisory, Foxit Security Bulletins).

Impact

Successful exploitation causes the affected Foxit PDF Reader or PDF Editor application to crash, resulting in a denial of service condition for the end user. There is no impact on confidentiality or data integrity, as the vulnerability only affects availability. The scope is limited to the application process itself, with no evidence of lateral movement potential or data exposure risk (GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014–0.019%, placing it in a very low percentile for exploitation likelihood. Exploitation requires user interaction (opening a malicious PDF), which further limits the attack surface (GitHub Advisory).

Exploitation steps

  1. Craft malicious PDF: Create a PDF document containing a stamp annotation (/Subtype /Stamp) with the required AP (appearance) dictionary entry intentionally omitted or set to null.
  2. Deliver the document: Distribute the crafted PDF to a target user via email attachment, file share, web download, or other social engineering means.
  3. User opens the file: The victim opens the malicious PDF in a vulnerable version of Foxit PDF Reader or Foxit PDF Editor.
  4. Trigger null pointer dereference: The application attempts to access the AP stream object for the stamp annotation without a prior null check, dereferencing a null pointer.
  5. Application crash: The null pointer dereference causes an unhandled exception, crashing the application and resulting in denial of service for the user (GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited PDF files containing stamp annotations, particularly from untrusted sources.
  • Logs: Application crash logs or Windows Event Viewer entries showing Foxit PDF Reader/Editor process termination with access violation or null pointer exception errors.
  • Process: Abnormal termination of FoxitPDFReader.exe or FoxitPDFEditor.exe processes shortly after opening a PDF document, potentially with crash dump files generated in the application's crash reporting directory.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability. Users should update Foxit PDF Editor to versions beyond 14.0.2, 13.2.2, 2025.3, 2024.4.1, and 2023.3.0, and update Foxit PDF Reader to versions beyond 2025.3. As interim mitigations, users should exercise caution when opening PDF files from untrusted or unknown sources, and organizations may consider implementing sandboxing for PDF processing or restricting PDF file handling to trusted sources. The official security bulletin is available at the Foxit support page (Foxit Security Bulletins, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management