Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Use‑After‑Free RCE in Foxit PDF Reader (CVE‑2026‑13128) Threatens Enterprise Endpoints

Foxit PDF Reader is vulnerable to a use‑after‑free flaw (CVE‑2026‑13128) that scores 7.8 on CVSS and allows remote code execution when a user opens a malicious file or page. The issue underscores the need for strong vulnerability‑management and patch‑evidence controls to satisfy audit and compliance requirements.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free RCE in Foxit PDF Reader (CVE‑2026‑13128) Threatens Enterprise Endpoints

What It Is — Foxit PDF Reader contains a use‑after‑free flaw in its handling of Annotation objects (CVE‑2026‑13128). The defect allows remote attackers to execute arbitrary code in the context of the PDF Reader process.

Exploitability — CVSS 7.8 (High). Exploitation requires user interaction: the victim must open a malicious PDF file or visit a crafted web page. No public exploit code has been observed, but the vulnerability is actively exploitable once the required user action occurs.

Affected Products — Foxit PDF Reader (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for robust vulnerability‑management controls that capture, prioritize, and remediate high‑severity flaws across endpoint software.
  • Provides evidence that timely patching is a core control objective; auditors expect documented proof of remediation within defined service‑level windows.
  • Highlights the importance of continuous configuration monitoring to ensure that all workstations run the patched version, supporting a defensible audit trail for compliance frameworks.

Recommended Actions

  • Deploy Foxit’s September 2026 security update to all PDF Reader installations immediately.
  • Verify patch deployment via automated asset‑inventory tools and record the evidence in your control repository.
  • Conduct a targeted scan for vulnerable versions across the environment and remediate any outliers.
  • Update your vulnerability‑management policy to include user‑interaction‑based exploits as a priority class.

Source: Zero Day Initiative advisory – ZDI‑26‑727

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-727/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →