CVE-2026-5937
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2026-5937 is a denial-of-service vulnerability in Foxit PDF Reader and Foxit PDF Editor caused by insufficient parameter verification during file processing. When a malformed file is opened, the application fails to handle a std::invalid_argument exception, causing the program to terminate. Affected products include Foxit PDF Reader (versions before 2026.1.1), Foxit PDF Editor (versions before 13.2.4, 14.0.0–14.0.3, and 2023.0.0–2026.1.0). The vulnerability was published on April 27, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Foxit Security Bulletins).

Technical details

The root cause is classified as CWE-248 (Uncaught Exception): the application performs insufficient validation of file parameters, allowing a specially crafted file to induce a format error that raises an unhandled std::invalid_argument C++ exception. The attack vector is local (AV:L), requiring no privileges but necessitating user interaction — specifically, a user must open or process the malicious file. No authentication or elevated privileges are required for the attacker to deliver the malicious file, but the victim must interact with it to trigger the crash (GitHub Advisory, Foxit Security Bulletins).

Impact

Successful exploitation results in an application crash (denial of service), with high availability impact and no confidentiality or integrity impact. The affected scope is limited to the Foxit PDF Reader or Editor process on the victim's local system; there is no evidence of lateral movement potential or data exposure risk. The vulnerability cannot be used to execute arbitrary code or access sensitive information (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.013–0.015%, placing it in the 3rd percentile for exploitation likelihood within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 310407) and Qualys (plugin 387163) (Feedly).

Exploitation steps

  1. Craft malformed file: Create a PDF or supported file with malformed parameters that violate expected format constraints, designed to trigger an invalid argument condition during parsing.
  2. Deliver the file: Distribute the malicious file to a target user via email attachment, file share, or web download — exploiting social engineering to encourage the user to open it.
  3. User opens the file: The victim opens the malicious file in Foxit PDF Reader or PDF Editor.
  4. Exception triggered: The application's file processing routine encounters the malformed parameter, raises a std::invalid_argument exception that is not caught, and the process terminates abruptly, resulting in a denial of service (GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or suspicious PDF/document files received from unknown sources in user download or temp directories.
  • Logs: Application crash logs or Windows Event Viewer entries (Event ID 1000/1001) referencing Foxit PDF Reader or Editor process termination with unhandled C++ exception (std::invalid_argument).
  • Process: Sudden, unexplained termination of FoxitPDFReader.exe or FoxitPDFEditor.exe processes without user-initiated close action.
  • Network: Unusual inbound file transfers or email attachments containing PDF files from untrusted or external sources preceding application crashes.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: Foxit PDF Reader 2026.1.1 and later, Foxit PDF Editor 13.2.4 and later (for the 13.x branch), 14.0.4 and later (for the 14.x branch), and 2026.1.1 and later (for the 2026.x branch). Users should update to the latest available version via the Foxit Security Bulletins page. As a temporary workaround, users should avoid opening PDF files from untrusted or unknown sources, and administrators should monitor application logs for crash events indicative of exploitation attempts (Foxit Security Bulletins, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management