Foxit Reader: 88 records in one advisory
88 records announced together, published between 2019-10-03 and 2021-05-21, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://www.foxitsoftware.com/support/security-bulletins.php. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
No record in this batch is listed by CISA in held sources.
17 of 88 records name something of its own. For the other 71, held sources say the same thing about each.
Most commonly mapped weakness across the batch: CWE-416: Use After Free.
What this page does not cover
This batch is 88 of the 636 records that cite the same advisory. The other 548 are different findings announced alongside it.
380 of them are on the sibling batches linked below. The remaining 168 are grouped with nothing and have only their own record pages.
Other batches under the same advisory: foxitsoftware-security-bulletins-0463ca62e1, foxitsoftware-security-bulletins-52bff22065, foxitsoftware-security-bulletins-fd32fa6e8f
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Foxit Reader code execution records from 2019 to 2021, and who was left reporting them
The records in this group were published between 3 October 2019 and 21 May 2021, and they share one opening sentence: this vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader. That is the advisory template of Trend Micro's Zero Day Initiative, the same template a larger group at this anchor carries for the 2017 buying wave, so a shared shape here means a shared publisher. What marks this later window is the credit line. CVE-2019-13326, a member of this group, was published as ZDI-19-849 on 1 October 2019, after Foxit was notified on 16 July 2019, and its researcher line reads Anonymous. By the May 2021 batch the programme was publishing Foxit advisories credited to its own staff: ZDI-21-527, for CVE-2021-31470, was reported to Foxit on 20 January 2021, published on 7 May 2021 and credited to Mat Powell of Trend Micro Zero Day Initiative. Both advisories carry a second template sentence, that the target must visit a malicious page or open a malicious file. Threatpost reported on 3 October 2019 that Foxit Reader 9.7 fixed eight high severity flaws, seven of them reported through the Zero Day Initiative and one by Cisco Talos, and that Foxit had patched over 100 vulnerabilities the year before.
These records were published together because one programme wrote and released them, not because they are one flaw. Each was reported on its own date, months apart in places, and the shared sentence says nothing about whether any two of them touch the same code or are closed by the same Foxit release.
The credit line is the gap here. Anonymous is a real entry in this programme's advisories, so a record marked that way cannot tell you whether an outside researcher sold the report or the programme's own staff found it. The advisories name the Foxit build that was vulnerable, 9.5.0.20723 in the 2019 case, but not the release that carried the fix, so a reader who wants to know what to upgrade to has to go back to Foxit's bulletin index.
Written from zerodayinitiative.com, zerodayinitiative.com, threatpost.com, foxitsoftware.com, foxit.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at medium confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
88 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.