Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129)
What It Is – A use‑after‑free flaw in the handling of Doc objects allows a remote attacker to read memory contents of the Foxit PDF Reader process. Exploitation requires the victim to open a malicious PDF or visit a crafted web page.
Exploitability – No public exploit code is known, but the CVSS 3.3 score (Low) reflects the need for user interaction and limited impact (confidentiality only).
Affected Products – Foxit PDF Reader (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a robust vulnerability‑management control: timely detection, patching, and evidence of remediation.
- Provides audit‑ready proof that the organization monitors third‑party software for security flaws, a key control in NIST CSF 2.0’s Identify and Protect functions.
- Enables continuous assurance that endpoint applications do not become inadvertent data‑leak vectors, supporting defensible evidence for regulators and enterprise buyers.
Recommended Actions
- Deploy Foxit’s September 2026 security update immediately on all endpoints.
- Verify patch deployment through automated inventory and configuration management tools.
- Record remediation evidence (patch version, deployment timestamps) in a centralized Trust Center for audit readiness.
- Review other PDF readers in use and apply the same patch‑management process.