Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129)
What It Is — Foxit PDF Reader contains a use‑after‑free flaw in its handling of Annotation objects that can disclose sensitive information. The vulnerability (CVE‑2026‑13129) receives a CVSS 3.3 (Low) rating.
Exploitability — No public exploit code, but exploitation requires a user to open a crafted PDF or visit a malicious page (user‑interaction required). CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N.
Affected Products — Foxit PDF Reader (all versions prior to the August 2026 patch).
Why It Matters for Compliance & Audit Readiness
- SOC 2 mandates documented vulnerability‑remediation (CC6.1) and confidentiality controls (CC6.2); this issue underscores the importance of timely patch management.
- Continuous collection of patch‑deployment evidence provides auditors with a defensible audit trail and demonstrates due‑diligence.
- Mapping the remediation to your control framework helps satisfy enterprise buyers who now demand verifiable SOC 2 compliance.
Recommended Actions
- Apply Foxit’s August 2026 security update to every endpoint immediately.
- Record the updated version in your asset inventory and map the remediation to the relevant SOC 2 controls.
- Deploy automated vulnerability scanning to capture future findings and generate continuous compliance evidence. Source: Zero Day Initiative advisory