CVE-2026-3776
published 2026-04-01CVE-2026-3776: The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.10%
1.2th percentile
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a crafted document to trigger a null pointer dereference and crash the application, resulting in denial of service.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | <= 13.2.2.24014 | — |
| foxit | pdf_editor | <= 13.2.2.63349 | — |
| foxit | pdf_editor | 14.0.0.33046 – 14.0.2.33402 | — |
| foxit | pdf_editor | 14.0.0.68868 – 14.0.2.69164 | — |
| foxit | pdf_editor | 2023.1.0.15510 – 2023.3.0.23028 | — |
| foxit | pdf_editor | 2023.1.0.55583 – 2023.3.0.63083 | — |
| foxit | pdf_editor | 2024.1.0.23997 – 2024.4.1.27687 | — |
| foxit | pdf_editor | 2024.1.0.63682 – 2024.4.1.66479 | — |
| foxit | pdf_editor | 2025.1.0.27937 – 2025.3.0.35737 | — |
| foxit | pdf_editor | 2025.1.0.66692 – 2025.3.0.69570 | — |
| foxit | pdf_reader | <= 2025.3.0.35737 | — |
| foxit | pdf_reader | <= 2025.3.0.69570 | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-01
Published