HomeIntelligenceBrief
VULNERABILITY BRIEF 🟢 Low Vulnerability

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129) Risks Sensitive Data

Foxit PDF Reader contains a use‑after‑free flaw (CVE‑2026‑13129) that can disclose information when a crafted PDF is opened. Scoring 3.3 (Low) and requiring user interaction, the vulnerability highlights the need for robust patch‑management and documented remediation to satisfy SOC 2 audit requirements.

Verisq™ Intelligence · 📅 August 25, 2026 · 📰 zerodayinitiative.com
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Use‑After‑Free Information Disclosure in Foxit PDF Reader (CVE‑2026‑13129)

What It Is — Foxit PDF Reader contains a use‑after‑free flaw in its handling of Annotation objects that can disclose sensitive information. The vulnerability (CVE‑2026‑13129) receives a CVSS 3.3 (Low) rating.

Exploitability — No public exploit code, but exploitation requires a user to open a crafted PDF or visit a malicious page (user‑interaction required). CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N.

Affected Products — Foxit PDF Reader (all versions prior to the August 2026 patch).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 mandates documented vulnerability‑remediation (CC6.1) and confidentiality controls (CC6.2); this issue underscores the importance of timely patch management.
  • Continuous collection of patch‑deployment evidence provides auditors with a defensible audit trail and demonstrates due‑diligence.
  • Mapping the remediation to your control framework helps satisfy enterprise buyers who now demand verifiable SOC 2 compliance.

Recommended Actions

  • Apply Foxit’s August 2026 security update to every endpoint immediately.
  • Record the updated version in your asset inventory and map the remediation to the relevant SOC 2 controls.
  • Deploy automated vulnerability scanning to capture future findings and generate continuous compliance evidence. Source: Zero Day Initiative advisory
📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-601/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →