Microsoft, Adobe, Apple, and Foxit vulnerabilities
Cisco Talos disclosed patched vulnerabilities in Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows.
Cisco Talos disclosed several now-patched vulnerabilities in Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows. Photoshop CVE-2026-48388 is a privilege escalation in the installer. Foxit CVE-2026-57256 and CVE-2026-91799 can lead to code execution via malicious PDF JavaScript. Windows issues include information disclosure in NETIO.sys (CVE-2026-50475) and tcpip.sys (CVE-2026-49177), plus privilege escalation and type confusion in the Cloud Files Mini Filter (CVE-2026-58613, CVE-2026-80093).
- Photoshop installer flaw CVE-2026-48388 allows privilege escalation via replaced files.
- Foxit Reader bugs CVE-2026-57256 and CVE-2026-91799 can yield code execution.
- Windows driver flaws affect NETIO.sys, Cloud Files filter, and tcpip.sys.
- Vendors have patched the issues; Talos did not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-483888.6<1%Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context…published · adobe photoshop installer
- CVE-2026-491775.5<1%Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally
Full article381 words · extracted from blog.talosintelligence.com · click to collapse
Wednesday, October 7, 2026 15:27
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.
Adobe Photoshop privilege escalation vulnerability
TALOS-2026-2360 (CVE-2026-48388) is a privilege escalation vulnerability in the Installation functionality of Photoshop (version(s): Photoshop_Set-Up.exe version 2.11.0.30). An attacker can replace files with a specially crafted malformed file to trigger this vulnerability and lead to privilege escalation.
Apple macOS CoreWLAN information disclosure vulnerability
TALOS-2026-2376 is an information disclosure vulnerability in the CoreWLAN functionality of macOS (version(s): 26.3.1(25D2128)). An attacker can call a sequence of APIs to trigger this vulnerability.
Foxit Reader code execution and use-after-free vulnerabilities
TALOS-2026-2420 (CVE-2026-57256) is a code execution vulnerability in the Javascript checkbox CBF_Widget functionality of Foxit Reader (version(s): 2026.1.1.36485). A specially crafted malformed file provided by an attacker can lead to remote code execution.
TALOS-2026-2446 (CVE-2026-91799) is a use-after-free vulnerability in the way Foxit Reader handles an Array object. A specially crafted JavaScript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.
Microsoft Windows out-of-bounds, use-after-free, and type confusion vulnerabilities
TALOS-2026-2443 (CVE-2026-50475) is an out-of-bounds pointer offset vulnerability in the Microsoft Windows NETIO.sys driver. A specially crafted I/O request packet (IRP) can cause disclosure of sensitive information.
TALOS-2026-2426 (CVE-2026-58613) is a use-after-free vulnerability in Windows Cloud Files Mini Filter Driver (version(s): 10.0.26100.8457 (WinBuild.160101.0800)). A specially crafted sequence of Cloud Filter API calls, executed with a dedicated application, can lead to privilege escalation.
TALOS-2026-2445 (CVE-2026-80093) is a type confusion vulnerability in Windows Cloud Files Mini Filter Driver (version(s): 10.0.26100.8457 (WinBuild.160101.0800) and 10.0.26100.8655 (WinBuild.160101.0800)). A specially crafted sequence of Cloud Filter API calls can lead to type confusion. An attacker can execute a dedicated application to trigger this vulnerability.
TALOS-2026-2427 (CVE-2026-49177) is an out-of-bounds read vulnerability in Microsoft Windows tcpip.sys driver. A specially crafted I/O request packet (IRP) can cause an arbitrary out-of-bounds read, potentially leading to information disclosure or a denial-of-service condition.