Remote Code Execution in Foxit PDF Reader (CVE‑2026‑91797) via Directory Traversal
What It Is – A directory‑traversal flaw in the handling of embedded files within PDF portfolios allows a remote attacker to execute arbitrary code on the victim’s machine. The vulnerability is tracked as CVE‑2026‑91797 and has a CVSS 7.8 (High) rating.
Exploitability – Exploitation requires user interaction (opening a malicious PDF or visiting a crafted page). No public exploit code is known, but the low attack complexity and high impact make it a priority for defenders.
Affected Products – Foxit PDF Reader (all versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a robust vulnerability‑management control: timely identification, patching, and evidence of remediation.
- Provides a concrete data point for continuous control monitoring—organizations can capture patch‑status evidence to prove due diligence during audits.
- Highlights the importance of secure configuration and validation of file‑handling logic, a control objective that maps to many frameworks (e.g., NIST CSF Identify ID.RM‑1, ISO 27001 A.12.6).
Recommended Actions
- Deploy Foxit’s September 2026 security update to all PDF Reader installations.
- Verify patch levels via an asset‑inventory scan and document remediation in your control evidence repository.
- Enable application‑allow‑list policies to block execution of unsigned binaries launched from PDF readers.
- Incorporate this CVE into your vulnerability‑management workflow and map the remediation to the “Patch Management” control objective.
Source: Zero Day Initiative advisory