CVE-2026-5940
published 2026-04-27CVE-2026-5940: Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.17%
6.6th percentile
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | < 13.2.4 | 13.2.4 |
| foxit | pdf_editor | >= 14.0.0 < 14.0.4 | 14.0.4 |
| foxit | pdf_editor | >= 2023.0.0 < 2026.1.1 | 2026.1.1 |
| foxit | pdf_reader | < 2026.1.1 | 2026.1.1 |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmwv-jpmc-ppqc: Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes
ghsa_unreviewed·2026-04-27
CVE-2026-5940 [HIGH] CWE-416 GHSA-gmwv-jpmc-ppqc: Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.
VulDB
Foxit PDF Editor/PDF Reader UI Handler use after free (EUVD-2026-25826)
vuldb·2026-04-27·CVSS 7.8
CVE-2026-5940 [HIGH] Foxit PDF Editor/PDF Reader UI Handler use after free (EUVD-2026-25826)
A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been rated as critical. Impacted is an unknown function of the component UI Handler. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-5940. The attack may be initiated remotely. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-27
Published