CVE-2026-13126: Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published Jul 8, 2026
·Updated
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.
Affected Software
9 affected components
Foxit Foxit PDF Editor/Reader
All of the following
Any of the following
Foxit PDF Editor<=13.2.4.24048
Foxit PDF Editor>=14.0.0.33046<=14.0.4.33508
Foxit PDF Editor>=2023.1.0.15510<=2023.3.0.23028
Foxit PDF Editor>=2024.1.0.23997<=2024.4.1.27687
Foxit PDF Editor>=2025.1.0.27937<=2025.3.0.35737
Foxit PDF Editor>=2026.1.0.36452<=2026.1.1.36485
Foxit PDF Reader<=2026.1.1.36485
Microsoft Windows
Event History
Jul 8, 2026
CVE Published
via MITRE·07:36 AM
Data Sourced
via MITRE·07:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13126?
CVE-2026-13126 has a high severity score of 7.8.
2
What kind of vulnerability is CVE-2026-13126?
CVE-2026-13126 is a Use-After-Free vulnerability related to remote code execution in Foxit PDF Editor/Reader.
3
How does CVE-2026-13126 affect Foxit PDF Editor/Reader?
CVE-2026-13126 can cause crashes and potentially allow remote code execution due to invalid operations on pop-up annotations.
4
How do I fix CVE-2026-13126?
To fix CVE-2026-13126, ensure that you update Foxit PDF Editor/Reader to the latest version provided by the vendor.
5
Is CVE-2026-13126 exploitable remotely?
Yes, CVE-2026-13126 is exploitable remotely due to the nature of how the vulnerability can be triggered via crafted PDF files.