Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Local Privilege Escalation in Foxit PDF Reader (CVE‑2026‑91813) via FoxitUpdater Race Condition

A race‑condition bug in Foxit PDF Reader’s updater lets a low‑privileged attacker gain SYSTEM rights. The flaw (CVE‑2026‑91813, CVSS 7.8) is patched by Foxit, underscoring the need for auditable patch‑management and least‑privilege controls for compliance readiness.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Local Privilege Escalation in Foxit PDF Reader (CVE‑2026‑91813) via FoxitUpdater Race Condition

What It Is – A race‑condition flaw in the FoxitUpdater component of Foxit PDF Reader allows a low‑privileged attacker who can run code on a workstation to obtain SYSTEM‑level privileges.

Exploitability – The vulnerability is locally exploitable; an attacker must first achieve code execution as a standard user. CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). No public exploits are known, but the attack path is straightforward once foothold is gained.

Affected Products – Foxit PDF Reader (any version prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Patch & Vulnerability Management – Demonstrates the need for continuous, auditable patching processes; a missed update creates a high‑impact privilege‑escalation gap.
  • Least‑Privilege Controls – Highlights the importance of enforcing least‑privilege on endpoint software and verifying that update mechanisms cannot be abused.
  • Defensible Evidence – Timely remediation provides concrete evidence for auditors that the organization maintains an effective control‑assurance posture.

Recommended Actions

  • Deploy Foxit’s September 2026 security update to all endpoints immediately.
  • Verify the patch resolves the race‑condition through internal testing or vendor validation.
  • Record the remediation in your patch‑management system and retain proof for audit trails.

Source: Zero Day Initiative Advisory – ZDI‑26‑742

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-742/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →