Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Information Disclosure in Foxit PDF Reader (CVE‑2026‑91796) Exposes NTLM Responses

A CVE‑2026‑91796 flaw in Foxit PDF Reader can disclose NTLM authentication responses when a victim opens a crafted file or web page. The issue underscores the need for robust credential‑protection controls and timely patching to satisfy audit‑readiness requirements.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Information Disclosure in Foxit PDF Reader (CVE‑2026‑91796) Exposes NTLM Responses

What It Is – A low‑severity (CVSS 3.3) information‑disclosure flaw in the importIcon method of Foxit PDF Reader that can reveal NTLM authentication responses.

Exploitability – Requires user interaction (opening a malicious file or visiting a crafted web page). No public exploit code is known, but an attacker who tricks a user can harvest NTLM hashes.

Affected Products – Foxit PDF Reader (all supported versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for credential‑protection controls (e.g., monitoring NTLM usage, enforcing MFA) that map to multiple frameworks (NIST CSF 2.0, ISO 27001, etc.).
  • Highlights the importance of continuous patch management as evidence of due‑diligence in an audit‑ready posture.
  • Provides a concrete data point for identity‑access assurance that can be captured in a Trust Center dashboard for enterprise buyers.

Recommended Actions

  • Deploy Foxit’s September 2026 security update immediately.
  • Harden NTLM usage: enable SMB signing, enforce multi‑factor authentication, and monitor for anomalous NTLM response traffic.
  • Incorporate the patch status into your continuous control‑monitoring platform to retain defensible evidence for audits.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-732/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →