Sceawere

Vulnerability Detail

CVE-2026-91812UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Foxit Update Mechanism MitM Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.9
Creation Date
2h ago
Vendor
Foxit Software Inc.
Product
Foxit PDF Editor
Attack Type
CWE-295 Improper Certificate Validation
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.9",
  "pubDate": "2026-09-23T08:17:13.423Z",
  "pubdate": "2026-09-23T08:17:13.423Z",
  "executiveSummary": "This vulnerability involves a critical flaw in the update mechanism of Foxit PDF Editor and Foxit PDF Reader. The security deficiency stems from inadequate validation of X.509 certificates and insufficient verification of digital signatures during the automated update process.\nBy intercepting network traffic between the client and the update server, a man-in-the-middle (MitM) attacker can bypass security integrity checks. This allows for the delivery of malicious update packages containing arbitrary code.\nSuccessful exploitation of this flaw grants an attacker the capability to execute malicious payloads with system-level privileges. Given that the update process operates with high-level permissions, the impact is comprehensive, potentially leading to full system compromise, data exfiltration, and persistent access.\nThis vulnerability represents a significant risk to the enterprise environment, as it subverts the trusted update channel. Attackers do not require prior authentication to the target system but must be positioned to intercept network traffic, typically through ARP poisoning, DNS spoofing, or compromised intermediate network infrastructure. The flaw effectively turns a trusted security maintenance feature into an attack vector.",
  "technicalDetails": "The vulnerability resides within the binary update component utilized by Foxit PDF Editor and Foxit PDF Reader. The root cause is a failure to properly implement certificate pinning or strictly validate the chain of trust for the update server's SSL/TLS connection. Furthermore, the application fails to perform robust cryptographic signature verification on the downloaded update package prior to execution.\nThe attack flow initiates when the Foxit application polls the configured update URL via the HTTP/HTTPS protocol. An attacker, positioned as a MitM, intercepts this request. Because the client does not rigorously validate the server certificate, the attacker can present a spoofed certificate. The application accepts this connection, allowing the attacker to intercept the update manifest request.\nThe attacker provides a malicious response containing a crafted update manifest. This manifest points the application to a server controlled by the attacker, hosting a malicious executable designed to masquerade as a legitimate software update. When the Foxit update agent downloads this package, it fails to verify the authenticity or integrity of the binary, likely due to flawed signature checks or the omission of the signature verification step altogether.\nUpon downloading the malicious payload, the update agent triggers the execution of the installer. Since the update mechanism typically operates under the context of the System or high-privilege Administrator account to facilitate software changes, the malicious code is executed with those same elevated privileges. This results in arbitrary code execution (ACE) on the host machine.\nThe post-exploitation impact is severe. An attacker can achieve complete system persistence, deploy malware or rootkits, harvest sensitive data, or move laterally within the network. Because the malicious activity is wrapped within the legitimate process path of the update agent, traditional signature-based detection mechanisms may fail to flag the process execution initially. The exploitation requires network-level access to the communication path, but once positioned, the lack of host-side verification ensures that the malicious payload is trusted implicitly by the update manager."
}
CVE-2026-91812: Foxit Update Mechanism MitM Vulnerability (HIGH Severity, CVSS: 7.9) | Sceawere