CVE-2026-57241: Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
Published Jul 8, 2026
·Updated
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; however, the renderer still trusts the outdated page count, and eventually the application crashes due to out-of-bounds access.
Affected Software
9 affected components
Foxit Foxit PDF Editor/Reader
All of the following
Any of the following
Foxit PDF Editor<=13.2.4.24048
Foxit PDF Editor>=14.0.0.33046<=14.0.4.33508
Foxit PDF Editor>=2023.1.0.15510<=2023.3.0.23028
Foxit PDF Editor>=2024.1.0.23997<=2024.4.1.27687
Foxit PDF Editor>=2025.1.0.27937<=2025.3.0.35737
Foxit PDF Editor>=2026.1.0.36452<=2026.1.1.36485
Foxit PDF Reader<=2026.1.1.36485
Microsoft Windows
Event History
Jul 8, 2026
CVE Published
via MITRE·07:36 AM
Data Sourced
via MITRE·07:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57241?
CVE-2026-57241 has a medium severity rating of 6.1.
2
How do I fix CVE-2026-57241?
To fix CVE-2026-57241, update to the latest version of Foxit PDF Editor/Reader as soon as it is released.
3
What are the potential impacts of CVE-2026-57241?
CVE-2026-57241 can lead to application crashes and potential data loss due to out-of-bounds read vulnerabilities.
4
Who is affected by CVE-2026-57241?
Users of Foxit PDF Editor and Reader may be affected by CVE-2026-57241.
5
When was CVE-2026-57241 published?
CVE-2026-57241 was published on July 8, 2026.