CVE-2026-91795

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-822

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Full discourse1 post
  • DFIR Lab@DFIR_Lab

    🚨 HIGH: CVE-2026-91795 (CVSS 7.8) Foxit PDF Editor/Reader FileOpen plugin vulnerable to arbitrary code execution via crafted PDFs. Invalid pointer state leads to read/write violations. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/MsxUoSO1Fm

    0000010
    142 followersView on X

Explore more