Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑57237) Exposes Sensitive Data

A use‑after‑free flaw in Foxit PDF Reader (CVE‑2026‑57237) can disclose limited sensitive information when a user opens a malicious PDF or visits a crafted page. The vulnerability scores 3.3 (CVSS) and requires user interaction, but can be chained to code execution. For SOC 2‑audited organizations, the issue highlights the need for robust access‑control policies and security‑awareness programs.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑57237) Threatens Sensitive Data

What It Is — A use‑after‑free flaw in the handling of Annotation objects allows a remote attacker to read limited sensitive information from the memory of Foxit PDF Reader. The vulnerability is tracked as CVE‑2026‑57237 and has a CVSS 3.3 rating.

Exploitability — Exploitation requires user interaction (opening a malicious PDF or visiting a crafted web page). No public exploit code has been released, but the flaw can be chained with other issues to achieve arbitrary code execution.

Affected Products — Foxit PDF Reader (all versions prior to the August 24 2026 patch).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 logical‑access controls (CC6.1) must demonstrate that applications are kept up‑to‑date and that untrusted code cannot bypass controls.
  • Continuous evidence of patch‑management and endpoint hardening is required to satisfy audit reviewers.
  • Security‑awareness training records become critical evidence that users can recognize and avoid malicious documents.

Recommended Actions

  • Deploy Foxit’s security update on all corporate endpoints immediately.
  • Enforce least‑privilege execution for PDF readers (sandboxing, restricted file‑type policies).
  • Refresh security‑awareness training to cover malicious PDF tactics and the importance of timely patching.
  • Capture patch‑deployment logs and training completion records as audit evidence.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-600/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →