Cisco Talos Discloses Foxit Reader and LibRaw Vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team has disclosed seven security vulnerabilities affecting widely used software components: one in Foxit Reader and six in the LibRaw library. The Foxit Reader flaw, identified as CVE-2026-3779 (TALOS-2026-2365), is a use-after-free vulnerability triggered by specially crafted JavaScript within malicious PDF files, potentially leading to arbitrary code execution. Additionally, six vulnerabilities were found in LibRaw, a library for processing RAW image files. These include four heap-based buffer overflows (CVE-2026-20911, CVE-2026-21413, CVE-2026-20889, CVE-2026-24660) and two integer overflows (CVE-2026-24450, CVE-2026-20884). Attackers can exploit these LibRaw flaws by providing malicious image files. All identified vulnerabilities have been patched by their respective vendors in adherence to Cisco’s third-party vulnerability disclosure policy. Users are advised to update their software immediately. Cisco also provides Snort rules to detect exploitation attempts, available on Snort.org, while detailed advisories are posted on the Talos Intelligence website.
Wire timeline
Cisco Talos Discloses Foxit Reader and LibRaw Vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team has disclosed seven security vulnerabilities affecting widely used software components: one in Foxit Reader and six in the LibRaw library. The Foxit Reader flaw, identified as CVE-2026-3779 (TALOS-2026-2365), is a use-after-free vulnerability triggered by specially crafted JavaScript within malicious PDF files, potentially leading to arbitrary code execution. Additionally, six vulnerabilities were found in LibRaw, a library for processing RAW image files. These include four heap-based buffer overflows (CVE-2026-20911, CVE-2026-21413, CVE-2026-20889, CVE-2026-24660) and two integer overflows (CVE-2026-24450, CVE-2026-20884). Attackers can exploit these LibRaw flaws by providing malicious image files. All identified vulnerabilities have been patched by their respective vendors in adherence to Cisco’s third-party vulnerability disclosure policy. Users are advised to update their software immediately. Cisco also provides Snort rules to detect exploitation attempts, available on Snort.org, while detailed advisories are posted on the Talos Intelligence website.
Cisco Talos Blog