HomeIntelligenceBrief
VULNERABILITY BRIEF🟢 Low Vulnerability

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129) Risks Sensitive Data

Foxit PDF Reader contains a use‑after‑free flaw (CVE‑2026‑13129) that can disclose information when a crafted PDF is opened. Scoring 3.3 (Low) and requiring user interaction, the vulnerability highlights the need for robust patch‑management and documented remediation to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129)

What It Is — Foxit PDF Reader contains a use‑after‑free flaw in its handling of Annotation objects that can disclose sensitive information. The vulnerability (CVE‑2026‑13129) receives a CVSS 3.3 (Low) rating.

Exploitability — No public exploit code, but exploitation requires a user to open a crafted PDF or visit a malicious page (user‑interaction required). CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N.

Affected Products — Foxit PDF Reader (all versions prior to the August 2026 patch).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 mandates documented vulnerability‑remediation (CC6.1) and confidentiality controls (CC6.2); this issue underscores the importance of timely patch management.
  • Continuous collection of patch‑deployment evidence provides auditors with a defensible audit trail and demonstrates due‑diligence.
  • Mapping the remediation to your control framework helps satisfy enterprise buyers who now demand verifiable SOC 2 compliance.

Recommended Actions

  • Apply Foxit’s August 2026 security update to every endpoint immediately.
  • Record the updated version in your asset inventory and map the remediation to the relevant SOC 2 controls.
  • Deploy automated vulnerability scanning to capture future findings and generate continuous compliance evidence. Source: Zero Day Initiative advisory
📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-601/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →