Home › Intelligence › Brief
VULNERABILITY BRIEF🟢 Low Vulnerability

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129) Enables Sensitive Data Leak

A use‑after‑free bug (CVE‑2026‑13129) in Foxit PDF Reader can expose memory contents when a victim opens a crafted PDF. The flaw underscores the importance of rigorous vulnerability‑management and audit‑ready patch evidence for compliance frameworks.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129)

What It Is – A use‑after‑free flaw in the handling of Doc objects allows a remote attacker to read memory contents of the Foxit PDF Reader process. Exploitation requires the victim to open a malicious PDF or visit a crafted web page.

Exploitability – No public exploit code is known, but the CVSS 3.3 score (Low) reflects the need for user interaction and limited impact (confidentiality only).

Affected Products – Foxit PDF Reader (all supported versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a robust vulnerability‑management control: timely detection, patching, and evidence of remediation.
  • Provides audit‑ready proof that the organization monitors third‑party software for security flaws, a key control in NIST CSF 2.0’s Identify and Protect functions.
  • Enables continuous assurance that endpoint applications do not become inadvertent data‑leak vectors, supporting defensible evidence for regulators and enterprise buyers.

Recommended Actions

  • Deploy Foxit’s September 2026 security update immediately on all endpoints.
  • Verify patch deployment through automated inventory and configuration management tools.
  • Record remediation evidence (patch version, deployment timestamps) in a centralized Trust Center for audit readiness.
  • Review other PDF readers in use and apply the same patch‑management process.

Source: Zero Day Initiative advisory – ZDI‑26‑726

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-726/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →