Home › Intelligence › Brief
VULNERABILITY BRIEF🟢 Low Vulnerability

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129) Risks Sensitive Data

Foxit PDF Reader contains a use‑after‑free flaw (CVE‑2026‑13129) that can disclose information when a crafted PDF is opened. Scoring 3.3 (Low) and requiring user interaction, the vulnerability highlights the need for robust patch‑management and documented remediation to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129)

What It Is — Foxit PDF Reader contains a use‑after‑free flaw in its handling of Annotation objects that can disclose sensitive information. The vulnerability (CVE‑2026‑13129) receives a CVSS 3.3 (Low) rating.

Exploitability — No public exploit code, but exploitation requires a user to open a crafted PDF or visit a malicious page (user‑interaction required). CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N.

Affected Products — Foxit PDF Reader (all versions prior to the August 2026 patch).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 mandates documented vulnerability‑remediation (CC6.1) and confidentiality controls (CC6.2); this issue underscores the importance of timely patch management.
  • Continuous collection of patch‑deployment evidence provides auditors with a defensible audit trail and demonstrates due‑diligence.
  • Mapping the remediation to your control framework helps satisfy enterprise buyers who now demand verifiable SOC 2 compliance.

Recommended Actions

  • Apply Foxit’s August 2026 security update to every endpoint immediately.
  • Record the updated version in your asset inventory and map the remediation to the relevant SOC 2 controls.
  • Deploy automated vulnerability scanning to capture future findings and generate continuous compliance evidence. Source: Zero Day Initiative advisory
📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-601/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →