Critical Remote Code Execution in Foxit PDF Reader (CVE‑2026‑91794)
What It Is — A buffer‑overflow flaw in the DeviceN colorspace parser of Foxit PDF Reader permits an attacker to write past the end of an allocated buffer and execute arbitrary code. The vulnerability is assigned CVE‑2026‑91794 and carries a CVSS 7.8 (High) score.
Exploitability — Exploitation requires user interaction (opening a malicious PDF or visiting a crafted web page). The attack vector is local‑network / user‑initiated, but a successful trigger yields full code execution in the context of the PDF Reader process. No public exploit code has been released, but a patch is already available.
Affected Products — Foxit PDF Reader (all versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a robust vulnerability‑management control that ensures timely identification, assessment, and remediation of software flaws.
- Provides concrete evidence that an organization’s patch‑deployment process can be audited and verified, a key requirement for defensible trust statements to customers and regulators.
- Highlights the importance of continuous monitoring of endpoint software inventories to prove due‑diligence in a supply‑chain risk context (mapped to NIST CSF 2.0 Identify function).
Recommended Actions
- Deploy Foxit’s September 2026 security update to all PDF Reader installations immediately.
- Verify patch rollout through automated endpoint‑inventory tools and capture evidence of remediation for audit purposes.
- Update your vulnerability‑management workflow to prioritize CVSS ≥ 7.0 findings and require documented closure within 30 days.
- Conduct a post‑patch validation scan to confirm the out‑of‑bounds write issue is fully mitigated.