A critical vulnerability, CVE-2026-57239, has been identified in Foxit PDF Reader that allows local users to escalate privileges to SYSTEM level. The flaw impacts several earlier versions of the software, specifically 2026.1.1 and prior, as well as versions 14.0.4 and 13.2.4. While there are currently no confirmed exploits in the wild, the risk is significant due to the widespread use of Foxit's tools. Users are advised to update to version 2026.2 or higher to mitigate this risk. The vulnerability takes advantage of improper handling of update components, potentially allowing attackers to execute code with elevated privileges.
Foxit PDF Reader flaw lets users reach SYSTEM via CVE-2026-57239
CyberSIXT Evidence Panel
Article by CyberSIXT