Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution in Foxit PDF Reader (CVE‑2026‑91797) via Directory Traversal

Foxit PDF Reader contains a directory‑traversal RCE (CVE‑2026‑91797) with a CVSS 7.8 score. The flaw can be triggered when a user opens a malicious PDF portfolio. Prompt patching and evidence collection are essential for audit readiness.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
zerodayinitiative.com

Remote Code Execution in Foxit PDF Reader (CVE‑2026‑91797) via Directory Traversal

What It Is – A directory‑traversal flaw in the handling of embedded files within PDF portfolios allows a remote attacker to execute arbitrary code on the victim’s machine. The vulnerability is tracked as CVE‑2026‑91797 and has a CVSS 7.8 (High) rating.

Exploitability – Exploitation requires user interaction (opening a malicious PDF or visiting a crafted page). No public exploit code is known, but the low attack complexity and high impact make it a priority for defenders.

Affected Products – Foxit PDF Reader (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a robust vulnerability‑management control: timely identification, patching, and evidence of remediation.
  • Provides a concrete data point for continuous control monitoring—organizations can capture patch‑status evidence to prove due diligence during audits.
  • Highlights the importance of secure configuration and validation of file‑handling logic, a control objective that maps to many frameworks (e.g., NIST CSF Identify ID.RM‑1, ISO 27001 A.12.6).

Recommended Actions

  • Deploy Foxit’s September 2026 security update to all PDF Reader installations.
  • Verify patch levels via an asset‑inventory scan and document remediation in your control evidence repository.
  • Enable application‑allow‑list policies to block execution of unsigned binaries launched from PDF readers.
  • Incorporate this CVE into your vulnerability‑management workflow and map the remediation to the “Patch Management” control objective.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-733/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →