VORANT. Threat Intelligence Sign in Get the full feed

Foxit patches dozens of PDF Editor flaws

medium vulnerability

CERT-FR warns of multiple vulnerabilities in Foxit PDF Editor and Reader that allow remote code execution, privilege escalation, and data exposure.

CERT-FR issued an advisory detailing a large batch of vulnerabilities in Foxit PDF Editor and Foxit PDF Reader affecting Windows and Mac versions prior to 13.2.5, 14.0.5, and 2026.1.2. The flaws collectively enable remote code execution, privilege escalation, and unauthorized disclosure of sensitive data, though the advisory does not specify individual technical root causes or provide evidence of active exploitation.

Foxit published a corresponding security bulletin on July 8, 2026, addressing 26 distinct CVEs. Organizations running affected Foxit products should apply the vendor-supplied patches promptly, as PDF readers/editors are commonly targeted attack surfaces for document-based exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-13126CVE-2026-13127CVE-2026-13128CVE-2026-13129CVE-2026-57237CVE-2026-57238CVE-2026-57239CVE-2026-57240CVE-2026-57241CVE-2026-57242CVE-2026-57243CVE-2026-57244CVE-2026-57245CVE-2026-57246CVE-2026-57247CVE-2026-57248CVE-2026-57249CVE-2026-57250CVE-2026-57251CVE-2026-57252CVE-2026-57253CVE-2026-57254CVE-2026-57255CVE-2026-57256CVE-2026-57257CVE-2026-57258CVE-2026-57259CVE-2026-57260

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0845

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free