Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Use‑After‑Free RCE in Foxit PDF Reader (CVE‑2026‑91792) Threatens Endpoints

A use‑after‑free flaw in Foxit PDF Reader’s annotation handling (CVE‑2026‑91792) allows remote code execution when a victim opens a malicious PDF or visits a crafted page. The vulnerability underscores the need for robust patch management, secure configuration, and user‑awareness controls to maintain audit‑ready compliance.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free RCE in Foxit PDF Reader (CVE‑2026‑91792) Threatens Endpoints

What It Is — A use‑after‑free flaw in the handling of Annotation objects allows a remote attacker to execute arbitrary code in the context of the Foxit PDF Reader process. Exploitation requires the victim to open a malicious PDF or visit a crafted web page.

Exploitability — CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). No public exploit code has been released, but the low attack complexity and high impact make it a serious concern.

Affected Products — Foxit PDF Reader (all supported versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Patch Management & Vulnerability Monitoring – Demonstrating that you have a continuous process to detect, assess, and remediate critical software flaws satisfies a core control objective that maps across NIST CSF, ISO 27001, and other frameworks.
  • Secure Configuration & Application Hardening – Controlling which file types and annotation features are enabled reduces the attack surface and provides audit‑ready evidence of risk mitigation.
  • Security Awareness – Because exploitation hinges on user interaction, training users to recognize suspicious PDFs is a key control that supports a defensible security posture.

Recommended Actions

  • Deploy the Foxit security update released 2026‑09‑23 to all endpoints.
  • Verify patch deployment through automated inventory and patch‑compliance tooling.
  • Restrict or disable PDF annotation features where not required.
  • Refresh security‑awareness training to emphasize safe handling of PDF files and links.
  • Log and monitor for anomalous PDF‑related activity as part of your endpoint detection program.

Source: Zero Day Initiative advisory ZDI‑26‑724

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-724/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →