Use‑After‑Free RCE in Foxit PDF Reader (CVE‑2026‑91792) Threatens Endpoints
What It Is — A use‑after‑free flaw in the handling of Annotation objects allows a remote attacker to execute arbitrary code in the context of the Foxit PDF Reader process. Exploitation requires the victim to open a malicious PDF or visit a crafted web page.
Exploitability — CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). No public exploit code has been released, but the low attack complexity and high impact make it a serious concern.
Affected Products — Foxit PDF Reader (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Patch Management & Vulnerability Monitoring – Demonstrating that you have a continuous process to detect, assess, and remediate critical software flaws satisfies a core control objective that maps across NIST CSF, ISO 27001, and other frameworks.
- Secure Configuration & Application Hardening – Controlling which file types and annotation features are enabled reduces the attack surface and provides audit‑ready evidence of risk mitigation.
- Security Awareness – Because exploitation hinges on user interaction, training users to recognize suspicious PDFs is a key control that supports a defensible security posture.
Recommended Actions
- Deploy the Foxit security update released 2026‑09‑23 to all endpoints.
- Verify patch deployment through automated inventory and patch‑compliance tooling.
- Restrict or disable PDF annotation features where not required.
- Refresh security‑awareness training to emphasize safe handling of PDF files and links.
- Log and monitor for anomalous PDF‑related activity as part of your endpoint detection program.