Information Disclosure in Foxit PDF Reader (CVE‑2026‑91796) Exposes NTLM Responses
What It Is – A low‑severity (CVSS 3.3) information‑disclosure flaw in the importIcon method of Foxit PDF Reader that can reveal NTLM authentication responses.
Exploitability – Requires user interaction (opening a malicious file or visiting a crafted web page). No public exploit code is known, but an attacker who tricks a user can harvest NTLM hashes.
Affected Products – Foxit PDF Reader (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for credential‑protection controls (e.g., monitoring NTLM usage, enforcing MFA) that map to multiple frameworks (NIST CSF 2.0, ISO 27001, etc.).
- Highlights the importance of continuous patch management as evidence of due‑diligence in an audit‑ready posture.
- Provides a concrete data point for identity‑access assurance that can be captured in a Trust Center dashboard for enterprise buyers.
Recommended Actions
- Deploy Foxit’s September 2026 security update immediately.
- Harden NTLM usage: enable SMB signing, enforce multi‑factor authentication, and monitor for anomalous NTLM response traffic.
- Incorporate the patch status into your continuous control‑monitoring platform to retain defensible evidence for audits.
Source: Zero Day Initiative advisory