Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution in Linux Mint Xreader PDF Parser (CVE‑2026‑19772) Threatens Desktop Users

A type‑confusion flaw in Linux Mint’s Xreader PDF viewer (CVE‑2026‑19772) allows remote attackers to execute code when a malicious PDF is opened. The vulnerability scores 7.8 CVSS and has been patched, underscoring the need for robust patch‑management and control‑assurance evidence.

LiveThreat™ Intelligence · 📅 September 19, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Remote Code Execution in Linux Mint Xreader PDF Parser (CVE‑2026‑19772)

What It Is — A type‑confusion flaw in the PDF parsing logic of Linux Mint’s Xreader viewer allows an attacker to execute arbitrary code when a crafted PDF is opened. The vulnerability is tracked as CVE‑2026‑19772 and carries a CVSS 7.8 (High) score.

Exploitability — Exploitation requires user interaction (opening a malicious PDF) but can be performed remotely; a proof‑of‑concept has been published.

Affected Products — Linux Mint Xreader (all versions prior to the 2026‑09‑18 patch).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a documented patch‑management control that can be continuously monitored and evidenced.
  • Provides a concrete example of a software‑supply‑chain risk that must be tracked across asset inventories to satisfy audit requirements.
  • Highlights the importance of control mapping: remediation of this flaw satisfies a single control objective that aligns with multiple frameworks (e.g., NIST CSF, ISO 27001), delivering a defensible trust signal to customers and regulators.

Recommended Actions

  • Deploy the Linux Mint Xreader update released on 2026‑09‑18.
  • Verify the patched version across all endpoints via automated inventory tools.
  • Record the remediation step in your control‑evidence repository to support audit readiness.
  • Subscribe to Linux Mint security advisories for future PDF‑viewer or related component disclosures.

Source: Zero Day Initiative Advisory – ZDI‑26‑715

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-715/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →