CVE-2026-5939: UAF in Foxit PDF Editor/Reader via XFA calculate event
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5939?
CVE-2026-5939 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2026-5939?
To fix CVE-2026-5939, update to the latest version of Foxit PDF Editor or Foxit Reader provided by the vendor.
What types of systems are affected by CVE-2026-5939?
CVE-2026-5939 affects both Foxit PDF Editor and Foxit Reader without specific version limitations.
What is a use-after-free condition in CVE-2026-5939?
In CVE-2026-5939, a use-after-free condition occurs when the application tries to access memory that has already been freed, leading to crashes or potential exploits.
What are the potential consequences of CVE-2026-5939?
The potential consequences of CVE-2026-5939 include application crashes and the execution of arbitrary code by an attacker.