Skip to main content
Mallory
High

Arbitrary Code Execution via PDF JavaScript Remote Script Loading

IdentifiersCVE-2026-12057CWE-829· Inclusion of Functionality from…

CVE-2026-12057 is an arbitrary code execution vulnerability in a PDF application, likely associated with a Foxit product per the referenced Foxit security bulletin. The issue arises when JavaScript embedded in a PDF is executed inside the application's sandbox, but the sandbox does not properly intercept certain dangerous interfaces. Because those interfaces remain reachable, a malicious PDF can cause remote scripts to be loaded and executed, defeating the intended sandbox restrictions. The described weakness is consistent with inclusion or execution of functionality from an untrusted control sphere, enabling attacker-controlled script content to participate in the document-processing flow and ultimately leading to arbitrary code execution.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can result in arbitrary code execution in the context of the vulnerable application after a user opens or otherwise renders a malicious PDF containing embedded JavaScript. Based on the provided CVSS vector (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), the impact includes high confidentiality, integrity, and availability consequences, indicating an attacker may be able to run code, access or alter data available to the application, and potentially destabilize or fully compromise the affected user session or host context.

Mitigation

If you can’t patch tonight, do this now.

Until patches are deployed, reduce exposure by disabling JavaScript execution in PDF documents where operationally feasible, blocking automatic retrieval or execution of remote script content, and restricting use of the vulnerable PDF application for untrusted documents. Additional mitigations include opening untrusted PDFs in isolated environments, enforcing application allowlisting and endpoint controls to limit post-exploitation execution, and filtering or quarantining externally sourced PDF attachments that contain active content.

Remediation

Patch, then assume compromise.

Apply the vendor-provided security update referenced in the Foxit security bulletin for CVE-2026-12057. Because the provided content does not identify exact affected and fixed versions, the specific remediation version information is currently not available in the supplied data. Organizations should update all affected Foxit PDF software to the latest patched release identified by the vendor bulletin and verify that PDF JavaScript sandbox protections are fully updated.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity6

Community discussion across Reddit, Mastodon, and other social sources.