# Foxit patches dozens of PDF Editor flaws

Published: 2026-07-08 · Severity: medium
Canonical: https://vorant.io/reports/1836a0fc-9756-5403-acde-1537f4cd292a/foxit-patches-dozens-of-pdf-editor-flaws

> CERT-FR warns of multiple vulnerabilities in Foxit PDF Editor and Reader that allow remote code execution, privilege escalation, and data exposure.

CERT-FR issued an advisory detailing a large batch of vulnerabilities in Foxit PDF Editor and Foxit PDF Reader affecting Windows and Mac versions prior to 13.2.5, 14.0.5, and 2026.1.2. The flaws collectively enable remote code execution, privilege escalation, and unauthorized disclosure of sensitive data, though the advisory does not specify individual technical root causes or provide evidence of active exploitation.

Foxit published a corresponding security bulletin on July 8, 2026, addressing 26 distinct CVEs. Organizations running affected Foxit products should apply the vendor-supplied patches promptly, as PDF readers/editors are commonly targeted attack surfaces for document-based exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13126, CVE-2026-13127, CVE-2026-13128, CVE-2026-13129, CVE-2026-57237, CVE-2026-57238, CVE-2026-57239, CVE-2026-57240, CVE-2026-57241, CVE-2026-57242, CVE-2026-57243, CVE-2026-57244, CVE-2026-57245, CVE-2026-57246, CVE-2026-57247, CVE-2026-57248, CVE-2026-57249, CVE-2026-57250, CVE-2026-57251, CVE-2026-57252, CVE-2026-57253, CVE-2026-57254, CVE-2026-57255, CVE-2026-57256, CVE-2026-57257, CVE-2026-57258, CVE-2026-57259, CVE-2026-57260

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0845

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1836a0fc-9756-5403-acde-1537f4cd292a/foxit-patches-dozens-of-pdf-editor-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
