Critical Use-After-Free RCE in Foxit PDF Reader (CVE-2026-13128) Threatens Endpoints
What It Is — Foxit PDF Reader contains a use‑after‑free flaw in its handling of Doc objects (CVE‑2026‑13128). An attacker who convinces a user to open a crafted PDF or visit a malicious web page can achieve arbitrary code execution in the context of the PDF Reader process.
Exploitability — The vulnerability scores 7.8 (CVSS v3.1) and requires user interaction; no public exploit code has been released, but the attack path is well‑understood and a vendor patch is available.
Affected Products — Foxit PDF Reader (all versions prior to the August 2026 security update).
Why It Matters for Compliance & Audit Readiness
- Continuous patch‑management evidence is a core SOC 2 CC6.1 control; unpatched endpoint software creates a gap that auditors will flag.
- Documented security‑awareness training mitigates the “user must open a malicious file” vector, satisfying the SOC 2 CC6.2 requirement for personnel security.
- Maintaining an up‑to‑date inventory of installed software and its remediation status provides audit‑ready proof of due diligence.
Recommended Actions
- Deploy Foxit’s August 2026 security update across all workstations immediately.
- Verify patch deployment via an automated asset‑inventory tool and retain logs as audit evidence.
- Refresh security‑awareness modules to include “malicious PDF” scenarios and track completion.
- Review SOC 2 access‑control policies to ensure least‑privilege execution for PDF readers.
Source: Zero Day Initiative advisory