Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.
Adobe Photoshop privilege escalation vulnerability
TALOS-2026-2360 (CVE-2026-48388) is a privilege escalation vulnerability in the Installation functionality of Photoshop (version(s): Photoshop_Set-Up.exe version 2.11.0.30). An attacker can replace files with a specially crafted malformed file to trigger this vulnerability and lead to privilege escalation.
Apple macOS CoreWLAN information disclosure vulnerability
TALOS-2026-2376 is an information disclosure vulnerability in the CoreWLAN functionality of macOS (version(s): 26.3.1(25D2128)). An attacker can call a sequence of APIs to trigger this vulnerability.
Foxit Reader code execution and use-after-free vulnerabilities
TALOS-2026-2420 (CVE-2026-57256) is a code execution vulnerability in the Javascript checkbox CBF_Widget functionality of Foxit Reader (version(s): 2026.1.1.36485). A specially crafted malformed file provided by an attacker can lead to remote code execution.
TALOS-2026-2446 (CVE-2026-91799) is a use-after-free vulnerability in the way Foxit Reader handles an Array object. A specially crafted JavaScript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.
Microsoft Windows out-of-bounds, use-after-free, and type confusion vulnerabilities
TALOS-2026-2443 (CVE-2026-50475) is an out-of-bounds pointer offset vulnerability in the Microsoft Windows NETIO.sys driver. A specially crafted I/O request packet (IRP) can cause disclosure of sensitive information.
TALOS-2026-2426 (CVE-2026-58613) is a use-after-free vulnerability in Windows Cloud Files Mini Filter Driver (version(s): 10.0.26100.8457 (WinBuild.160101.0800)). A specially crafted sequence of Cloud Filter API calls, executed with a dedicated application, can lead to privilege escalation.
TALOS-2026-2445 (CVE-2026-80093) is a type confusion vulnerability in Windows Cloud Files Mini Filter Driver (version(s): 10.0.26100.8457 (WinBuild.160101.0800) and 10.0.26100.8655 (WinBuild.160101.0800)). A specially crafted sequence of Cloud Filter API calls can lead to type confusion. An attacker can execute a dedicated application to trigger this vulnerability.
TALOS-2026-2427 (CVE-2026-49177) is an out-of-bounds read vulnerability in Microsoft Windows tcpip.sys driver. A specially crafted I/O request packet (IRP) can cause an arbitrary out-of-bounds read, potentially leading to information disclosure or a denial-of-service condition.