← Browse

CVE-2026-18622

Low

No strong exploitation signal.

CVSS base
4.7 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS — probability of exploitation (30 days)
0.1%
2.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-451
Published 2026-08-13 · modified 2026-09-10

CVSS breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack VectorLLocal
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionRRequired
ScopeUUnchanged
ConfidentialityNNone
IntegrityHHigh
AvailabilityNNone

Timeline

Description

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.

Affected

apple foxit microsoft

References

Official: NVD · CVE.org