Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-91795 represents a critical vulnerability in Foxit PDF Editor and Reader's FileOpen plugin, where inadequate validation of encryption metadata in maliciously crafted PDF files can corrupt internal pointer states. This vulnerability matters because PDF readers are ubiquitous attack surfaces—users routinely open PDFs from untrusted sources, making this an effective vector for arbitrary code execution. Organizations relying on Foxit for document handling, particularly those in finance, legal, and healthcare sectors that process sensitive documents, face significant risk of compromise through seemingly innocuous file attachments.
While this CVE does not map to specific MITRE ATT&CK techniques in the current framework, Casky's platform would detect attack patterns associated with this vulnerability through behavioral analysis of memory corruption indicators and code execution anomalies. Practitioners using Casky would observe findings related to suspicious process behavior following PDF file handling—including unexpected memory access patterns, process spawning from the PDF reader application, and indicators consistent with exploitation attempts. Extended reasoning capabilities would correlate these signals with known exploit patterns for unvalidated parser inputs, allowing security teams to identify compromise attempts even before formal technique attribution, and enabling rapid response to FileOpen plugin-based attacks in their environments.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-91795. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation