Critical Information Disclosure Vulnerability (CVE‑2026‑91810) in Foxit PDF Reader
What It Is — Foxit PDF Reader contains an out‑of‑bounds read flaw in its handling of Doc objects. An attacker who convinces a user to open a malicious PDF or visit a crafted web page can cause the application to read memory beyond its allocation and disclose sensitive data.
Exploitability — CVSS 3.3 (Low‑Moderate). Remote exploitation is possible but requires user interaction; no public exploit code is known.
Affected Products — Foxit PDF Reader (all supported versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a vulnerability‑management control that ensures timely detection, risk assessment, and patch deployment across endpoint software.
- Provides audit‑ready evidence that an organization monitors vendor advisories and applies mitigations, a key requirement for governance under NIST CSF 2.0.
- Continuous evidence of remediation supports defensible compliance reporting and reduces the risk of downstream data‑exfiltration claims.
Recommended Actions
- Deploy the Foxit security update immediately on all endpoints.
- Verify patch installation via automated inventory tools and capture the remediation status as control evidence.
- Update your vulnerability‑management process to include user‑interaction‑required flaws and map them to the “Patch Management” control objective.
- Monitor for anomalous PDF‑reader activity (e.g., unexpected memory reads) using endpoint detection and response (EDR) solutions.