Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Improper Certificate Validation in Foxit PDF Reader Updater Enables Local Privilege Escalation (CVE‑2026‑91812)

A certificate‑validation flaw in Foxit PDF Reader’s updater (CVE‑2026‑91812) allows an attacker to execute code as SYSTEM after a user opens a malicious file or page. The issue underscores the importance of auditable patch‑management controls for compliance and audit readiness.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Improper Certificate Validation in Foxit PDF Reader Updater Enables Local Privilege Escalation (CVE‑2026‑91812)

What It Is – A vulnerability in the FoxitUpdater component of Foxit PDF Reader fails to properly validate the server’s TLS certificate. An attacker who can induce a user to visit a malicious page or open a crafted file can cause the updater to accept a forged certificate and execute arbitrary code with SYSTEM privileges.

Exploitability – Requires user interaction (malicious page or file) but the underlying flaw is exploitable on any vulnerable installation. CVSS 7.1 (High) with Network‑adjacent vector, High impact on confidentiality, integrity, and availability.

Affected Products – Foxit PDF Reader (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a secure software‑update process that is continuously monitored and auditable.
  • A gap in patch management can break multiple control objectives (e.g., “Maintain up‑to‑date and trusted software” across NIST CSF, ISO 27001, and SOC 2).
  • Enterprise buyers increasingly demand verifiable evidence that update mechanisms are protected, not just that a patch exists.

Recommended Actions

  • Deploy Foxit’s September 2026 security update immediately.
  • Verify the digital signature of the updater binary and enforce strict certificate validation in your endpoint management tools.
  • Capture patch‑deployment logs as immutable evidence for audit trails.
  • Incorporate the update‑validation control into your continuous compliance monitoring platform.

Source: Zero Day Initiative Advisory – ZDI‑26‑741

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-741/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →