Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Uncovering the risks: Exploring vulnerabilities in Foxit and LibRaw

Apr 18, 2026 | Threat Intelligence Research

Foxit Reader and LibRaw Vulnerabilities Disclosed by Cisco Talos

Recent research by Cisco Talos has uncovered significant vulnerabilities within Foxit Reader and the LibRaw library. These vulnerabilities have been addressed through patches from their respective vendors, in line with Cisco’s third-party vulnerability disclosure policy.

The Foxit Reader vulnerability is identified as a use-after-free issue (CVE-2026-3779) arising from improper handling of an Array object when interpreting JavaScript within malicious PDF files. This flaw enables memory corruption, which could lead to arbitrary code execution if a user is deceived into opening a compromised file. This specific vulnerability highlights the importance of user awareness regarding the risks posed by malicious documents.

In addition, Cisco Talos identified six vulnerabilities within the LibRaw library, which is widely used for processing RAW images from digital cameras. These include four distinct heap-based buffer overflow vulnerabilities and two integer overflow vulnerabilities, cataloged as CVE-2026-20911, CVE-2026-21413, CVE-2026-20889, CVE-2026-24660, CVE-2026-24450, and CVE-2026-20884. Similar to the Foxit Reader vulnerability, attackers may exploit these flaws by distributing specifically crafted files designed to trigger these vulnerabilities and enable unauthorized operations.

Defensive Context
Organizations utilizing Foxit Reader or LibRaw need to prioritize awareness of these vulnerabilities due to the associated risks of exploitation, especially in environments where documents are frequently exchanged or processed. Users who might be affected include those in creative, photographic, and documentation fields where digital signatures or camera RAW processing are routine. However, users in less document-intensive sectors may face a lower immediate risk.

Why This Matters
The implications of these vulnerabilities are critical for sectors heavily reliant on document processing. Any organization utilizing these applications may find themselves exposed to significant security risks, particularly if their users are not adequately trained to recognize potential threats from malicious files. Moreover, the prevalence of PDF formats and RAW images in workflows increases the likelihood of encountering targeted attacks exploiting these vulnerabilities.

Defender Considerations
Cisco Talos has provided basic directional guidance, suggesting that users update their applications to the latest versions to mitigate these vulnerabilities. Specific detection mechanisms have not been explicitly outlined, but organizations utilizing Snort can leverage the latest rule sets for potential coverage against exploitation attempts.

Indicators of Compromise (IOCs)
– CVE-2026-3779 related to Foxit Reader
– CVEs related to LibRaw:
– CVE-2026-20911
– CVE-2026-21413
– CVE-2026-20889
– CVE-2026-24660
– CVE-2026-24450
– CVE-2026-20884

Organizations should be vigilant in their monitoring efforts surrounding these CVEs to further enhance their security posture.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles