Foxit PDF Reader 2026.1.1 and Foxit PDF Editor versions 2026.1.1 and 14.0.4 available
Update recommended, because ,alicious vulnerabilities threaten Foxit PDF Reader and PDF Editor.
Critical security flaws have been discovered in Foxit PDF Reader and PDF Editor that could be exploited by attackers. Updates addressing these issues are now available, and users are strongly advised to install them without delay to reduce the risk of attacks. Although no active exploitation has been reported so far, unpatched systems remain vulnerable.
Multiple vulnerabilities addressed
According to Foxit's security advisory, the issues have been fixed in Foxit PDF Reader 2026.1.1 and Foxit PDF Editor versions 2026.1.1 and 14.0.4. In total, seven vulnerabilities affecting Windows systems have been resolved.
If exploited, these flaws could allow attackers to trigger denial-of-service (DoS) conditions, leading to application crashes (e.g., CVE-2026-5938, rated medium), or even execute arbitrary malicious code (e.g., CVE-2026-5943, rated high). Exploitation requires victims to open a specially crafted XFA file, which lacks proper validation during processing, enabling attackers to inject harmful code.
Foxit had previously addressed other high-severity vulnerabilities in its Reader and Editor products for both Windows and macOS in March and in December.