CVE-2026-3779

Publication date

2026-04-01 01:40:29

Family

Foxit

State

PUBLISHED

Description

The applications list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.