CVE-2026-91812
Received Received - Intake

Foxit PDF Editor Remote Code Execution via MITM Update Bypass

Vulnerability report for CVE-2026-91812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Foxit

Description

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
foxit pdf_editor_reader *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in Foxit PDF Editor/Reader's update system. Attackers can intercept updates and bypass security checks like certificate validation and package integrity verification. This could allow them to execute arbitrary code on a victim's system with high privileges.

Impact Analysis

If exploited, this vulnerability could let attackers install malware, steal sensitive data, or take full control of your system. It specifically targets the update process, so users relying on Foxit's software for document handling are at risk.

Compliance Impact

This vulnerability could undermine compliance with GDPR and HIPAA by allowing unauthorized code execution with system privileges, potentially leading to data breaches or unauthorized access to sensitive information. Failure to address such vulnerabilities may result in violations of data protection requirements.

Mitigation Strategies

Disable automatic updates in Foxit PDF Editor/Reader until a patch is released. Monitor network traffic for unusual certificate validation bypass attempts. Restrict Foxit application permissions to least privilege.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart