boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-18622

Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  N  H  N    5.5   .0012    1.8     —
AFFECTED
  Product           Versions                         Fixed
  Foxit PDF Editor  Versions 2026.1.2 and earlier –  —
  Foxit PDF Reader  Versions 2026.1.2 and earlier –  —
TIMELINE
  Aug 3   Reserved by Foxit
  Aug 13  Published (CNA: Foxit)
  Sep 10  RESCORED — CVE-2026-18622 (Foxit Software Inc. Foxit PDF Editor). CVSS 4.7 → 5.5 (NVD).
CWE-451 · CNA: Foxit · CVSS v3.1 · 1 reference · NVD status: Analyzed

Description

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 3, 2026ReservedReserved by Foxit
August 13, 2026PublishedPublished (CNA: Foxit)
September 10, 2026RESCOREDRESCORED — CVE-2026-18622 (Foxit Software Inc. Foxit PDF Editor). CVSS 4.7 → 5.5 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Foxit Software Inc.Foxit PDF Editor—Versions 2026.1.2 and earlier—
Foxit Software Inc.Foxit PDF Reader—Versions 2026.1.2 and earlier—

Weaknesses

CWE-451

References (1)

Related

Authoritative record: CVE-2026-18622 at cve.org

Vendors: foxit software

Weaknesses: CWE-451

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-18622 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.