← console
voxell vciy

CVE-2025-9326: Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability

ROUTINE

Telemetry drift only. No threshold crossed and no authority ruling changed.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. Upgrade to pdf reader 2025.1.0.27937 or later upper bounds of the CVE record's affected ranges
  2. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  3. Check your version against the ranges this record publishes.

What it is stated by the CNA

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26784.

weakness
CWE-125: Out-of-bounds Read
affected
Foxit PDF Reader
versions
Foxit PDF Reader 2024.4.0.27683
published ranges
foxit pdf editor <= 13.1.7.23637; foxit pdf editor >= 2023.1.0.15510 <= 2023.3.0.23028; foxit pdf editor >= 2024.1.0.23997 <= 2024.4.1.27687; foxit pdf editor 2025.1.0.27937; and 6 more on the CVE page
first unaffected version, by branch
pdf reader 2025.1.0.27937
severity
7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
assigned by
zdi
published
2025-09-02

check us zerodayinitiative.com foxit.com

Exploit code held, dated

exploit code
None held in the PoC-in-GitHub feed. A public repository changes this brief.

What moved held, dated

dateEPSSevent
3 Sep 20250.00063
8 Sep 20250.00068
4 Oct 20250.00074
9 Nov 20250.00085
2 Jan 20260.00122
17 Jan 20260.00058
30 Jan 20260.00056
10 Feb 20260.00066
29 Mar 20260.00075
8 May 20260.00076
19 May 20260.00093
15 Jun 20260.00235scoring model v2026.06.15
3 Aug 20260.00255

13 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.00 on 2026-08-03 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
fix
Held: pdf reader 2025.1.0.27937 (CVE record, loaded 2026-09-20). A newer fix from the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2025-9326', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.