CVE-2026-57242: Foxit PDF Editor/Reader Page Use-After-Free Vulnerability
Published Jul 8, 2026
·Updated
The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, eventually leading to a crash.
Affected Software
9 affected components
Foxit Foxit PDF Editor/Reader
All of the following
Any of the following
Foxit PDF Editor<=13.2.4.24048
Foxit PDF Editor>=14.0.0.33046<=14.0.4.33508
Foxit PDF Editor>=2023.1.0.15510<=2023.3.0.23028
Foxit PDF Editor>=2024.1.0.23997<=2024.4.1.27687
Foxit PDF Editor>=2025.1.0.27937<=2025.3.0.35737
Foxit PDF Editor>=2026.1.0.36452<=2026.1.1.36485
Foxit PDF Reader<=2026.1.1.36485
Microsoft Windows
Event History
Jul 8, 2026
CVE Published
via MITRE·07:36 AM
Data Sourced
via MITRE·07:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57242?
CVE-2026-57242 has a high severity rating of 7.8.
2
How do I fix CVE-2026-57242?
To fix CVE-2026-57242, ensure that you update to the latest version of Foxit PDF Editor/Reader as it contains the necessary patches.
3
What type of vulnerability is CVE-2026-57242?
CVE-2026-57242 is a use-after-free vulnerability affecting Foxit PDF Editor/Reader.
4
What are the consequences of exploiting CVE-2026-57242?
Exploitation of CVE-2026-57242 can lead to application crashes and potential denial of service.
5
Which software is affected by CVE-2026-57242?
CVE-2026-57242 affects Foxit PDF Editor and Reader.