CVE-2026-5942
published 2026-04-27CVE-2026-5942: Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.18%
8.0th percentile
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | < 13.2.4 | 13.2.4 |
| foxit | pdf_editor | >= 14.0.0 < 14.0.4 | 14.0.4 |
| foxit | pdf_editor | >= 2023.0.0 < 2026.1.1 | 2026.1.1 |
| foxit | pdf_reader | < 2026.1.1 | 2026.1.1 |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Foxit PDF Editor/PDF Reader Page Lifecycle Management use after free (EUVD-2026-25828)
vuldb·2026-04-27·CVSS 5.5
CVE-2026-5942 [MEDIUM] Foxit PDF Editor/PDF Reader Page Lifecycle Management use after free (EUVD-2026-25828)
A vulnerability classified as critical has been found in Foxit PDF Editor and PDF Reader. This affects an unknown function of the component Page Lifecycle Management. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-5942. Remote exploitation of the attack is possible. No exploit is available.
GHSA
GHSA-v92h-4968-3789: Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to acces
ghsa_unreviewed·2026-04-27
CVE-2026-5942 [MEDIUM] CWE-416 GHSA-v92h-4968-3789: Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to acces
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-27
Published