Foxit patches dozens of PDF Editor flaws
CERT-FR warns of multiple vulnerabilities in Foxit PDF Editor and Reader that allow remote code execution, privilege escalation, and data exposure.
CERT-FR issued an advisory detailing a large batch of vulnerabilities in Foxit PDF Editor and Foxit PDF Reader affecting Windows and Mac versions prior to 13.2.5, 14.0.5, and 2026.1.2. The flaws collectively enable remote code execution, privilege escalation, and unauthorized disclosure of sensitive data, though the advisory does not specify individual technical root causes or provide evidence of active exploitation.
Foxit published a corresponding security bulletin on July 8, 2026, addressing 26 distinct CVEs. Organizations running affected Foxit products should apply the vendor-supplied patches promptly, as PDF readers/editors are commonly targeted attack surfaces for document-based exploitation.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0845
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free