
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57260 is an out-of-bounds write vulnerability in Foxit PDF Editor and Foxit PDF Reader that can cause application crashes when processing a specially crafted PDF file containing a malformed Unity 3D object. During parsing, the application incorrectly resolves a portion of the abnormal object as a pointer and dereferences it as a valid memory address, triggering a crash. Affected products include Foxit PDF Editor (versions 13.2.3/13.2.4 and earlier, 14.0.3/14.0.4 and earlier, 2023.x, 2024.x, 2025.x, and 2026.1.1 and earlier) and Foxit PDF Reader (versions 2026.1.1 and earlier). The vulnerability was published on July 8, 2026, and carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Foxit Security Bulletins).
The root cause is classified as CWE-787 (Out-of-bounds Write): when Foxit PDF Editor or Reader parses a PDF containing an abnormal Unity 3D embedded object, it incorrectly interprets a portion of the malformed object's data as a memory pointer and attempts to use it as a valid address, writing data out of bounds and ultimately crashing the application. The attack vector is local (the victim must open a malicious PDF file), requires no privileges, but does require user interaction — a social engineering step to convince the target to open the crafted file. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Foxit Security Bulletins).
Successful exploitation results in high impacts to confidentiality, integrity, and availability within the scope of the affected application. The primary observed impact is a denial of service via application crash; however, the CVSS scoring also reflects potential for code execution given the out-of-bounds write primitive, which could theoretically allow an attacker to execute arbitrary code in the context of the user running Foxit PDF Editor or Reader. Lateral movement potential is limited given the local attack vector, but data exposure risk exists if code execution is achieved (GitHub Advisory, Foxit Security Bulletins).
FoxitPDFEditor.exe, FoxitPDFReader.exe) with access violation or out-of-bounds write exceptions.FoxitPDFEditor.exe or FoxitPDFReader.exe shortly after opening a PDF file; crash dump files (.dmp) generated in the user's temp directory or application data folder.Foxit has released patched versions addressing this vulnerability; users should update Foxit PDF Editor and Foxit PDF Reader to versions beyond 2026.1.1, 14.0.4, and 13.2.4 respectively, as detailed in the Foxit security bulletin (Foxit Security Bulletins). As a workaround, organizations should implement file validation controls to restrict opening PDFs from untrusted sources, and users should be educated to avoid opening PDF files from unknown or unverified senders. Disabling or sandboxing PDF rendering for untrusted files can further reduce risk while patches are applied.
Security news outlets including CyberSecurityNews, GBHackers, HealSecurity, and VPNcentral covered this vulnerability as part of broader reporting on Foxit patching over 20 code execution vulnerabilities in PDF Reader and Editor (CyberSecurityNews, GBHackers). The Hacker News included it in a weekly vulnerability recap (The Hacker News). CISA referenced the vulnerability in its weekly bulletin SB26-194 (CISA Bulletin). No significant individual researcher commentary or social media debate has been identified beyond standard vulnerability aggregation coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."