Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution Vulnerability (CVE‑2026‑91794) in Foxit PDF Reader Allows Arbitrary Code Execution

Foxit PDF Reader versions prior to the September 2026 update contain a DeviceN colorspace out‑of‑bounds write flaw (CVE‑2026‑91794) that can be triggered by a malicious PDF or web page, granting an attacker arbitrary code execution. The issue underscores the importance of rapid patch management and auditable evidence of remediation for compliance readiness.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in Foxit PDF Reader (CVE‑2026‑91794)

What It Is — A buffer‑overflow flaw in the DeviceN colorspace parser of Foxit PDF Reader permits an attacker to write past the end of an allocated buffer and execute arbitrary code. The vulnerability is assigned CVE‑2026‑91794 and carries a CVSS 7.8 (High) score.

Exploitability — Exploitation requires user interaction (opening a malicious PDF or visiting a crafted web page). The attack vector is local‑network / user‑initiated, but a successful trigger yields full code execution in the context of the PDF Reader process. No public exploit code has been released, but a patch is already available.

Affected Products — Foxit PDF Reader (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a robust vulnerability‑management control that ensures timely identification, assessment, and remediation of software flaws.
  • Provides concrete evidence that an organization’s patch‑deployment process can be audited and verified, a key requirement for defensible trust statements to customers and regulators.
  • Highlights the importance of continuous monitoring of endpoint software inventories to prove due‑diligence in a supply‑chain risk context (mapped to NIST CSF 2.0 Identify function).

Recommended Actions

  • Deploy Foxit’s September 2026 security update to all PDF Reader installations immediately.
  • Verify patch rollout through automated endpoint‑inventory tools and capture evidence of remediation for audit purposes.
  • Update your vulnerability‑management workflow to prioritize CVSS ≥ 7.0 findings and require documented closure within 30 days.
  • Conduct a post‑patch validation scan to confirm the out‑of‑bounds write issue is fully mitigated.

Source: Zero Day Initiative advisory – ZDI‑26‑730

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-730/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →