OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-91789 (CVSS 7.8)

NVD · officialPublished Sep 23, 2026Risk 23/100EPSS 0.2%

Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bounds write during pixel processing, potentially resulting in remote code execution.

CVSS
7.8
AV:LocalAC:LowPR:NoneUI:RequiredC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source