Cisco Talos' Vulnerability Discovery and Research team recently disclosed multiple security vulnerabilities affecting software from Adobe, Apple, Foxit Reader, and Microsoft. Cisco stated on October 7, 2026, that the respective vendors have patched all the identified flaws.
Adobe and Apple flaws
In Adobe software, Talos reported TALOS-2026-2360 (CVE-2026-48388), a privilege escalation vulnerability in the installation functionality of Photoshop_Set-Up.exe version 2.11.0.30. Talos reported that an attacker can trigger this flaw and gain elevated privileges by replacing files with a specially crafted malformed file.
Talos also identified TALOS-2026-2376, an information disclosure vulnerability in the CoreWLAN functionality of Apple macOS version 26.3.1(25D2128). According to Talos, an attacker can trigger this vulnerability by calling a sequence of APIs.
Foxit Reader vulnerabilities
Two code execution flaws were detailed in Foxit Reader. TALOS-2026-2420 (CVE-2026-57256) is a code execution vulnerability affecting the Javascript checkbox CBF_Widget functionality in Foxit Reader version 2026.1.1.36485, triggered when an attacker provides a specially crafted malformed file.
The second flaw, TALOS-2026-2446 (CVE-2026-91799), is a use-after-free issue in the way Foxit Reader handles an Array object. Specially crafted JavaScript code placed inside a malicious PDF document can cause memory corruption and result in arbitrary code execution.
Microsoft Windows driver issues
Talos detailed four vulnerabilities in Microsoft Windows drivers. TALOS-2026-2443 (CVE-2026-50475) is an out-of-bounds pointer offset vulnerability in the NETIO.sys driver where a specially crafted I/O request packet (IRP) can disclose sensitive information. TALOS-2026-2427 (CVE-2026-49177) is an out-of-bounds read flaw in tcpip.sys that can cause information disclosure or a denial-of-service condition when a crafted IRP is processed.
The remaining two Windows bugs affect the Cloud Files Mini Filter Driver. TALOS-2026-2426 (CVE-2026-58613) is a use-after-free vulnerability affecting version 10.0.26100.8457 that allows privilege escalation via a sequence of Cloud Filter API calls run with a dedicated application. TALOS-2026-2445 (CVE-2026-80093) is a type confusion vulnerability in driver versions 10.0.26100.8457 and 10.0.26100.8655 that an attacker can trigger using a dedicated application executing Cloud Filter API calls.
What to do
- Apply vendor security updates, as the vulnerabilities have been patched by Adobe, Apple, Foxit, and Microsoft.
- Download the latest rule sets from Snort.org for coverage to detect exploitation of these vulnerabilities.
Key facts and where they come from
- All disclosed vulnerabilities have been patched by the respective vendors under Cisco's disclosure policy.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy.
- Adobe Photoshop installer version 2.11.0.30 contains a privilege escalation flaw tracked as CVE-2026-48388.
TALOS-2026-2360 (CVE-2026-48388) is a privilege escalation vulnerability in the Installation functionality of Photoshop (version(s): Photoshop_Set-Up.exe version 2.11.0.30).
- Foxit Reader version 2026.1.1.36485 contains a remote code execution vulnerability in its Javascript checkbox widget.
TALOS-2026-2420 (CVE-2026-57256) is a code execution vulnerability in the Javascript checkbox CBF_Widget functionality of Foxit Reader (version(s): 2026.1.1.36485).
- A crafted I/O request packet can trigger an out-of-bounds read in the Windows tcpip.sys driver.
TALOS-2026-2427 (CVE-2026-49177) is an out-of-bounds read vulnerability in Microsoft Windows tcpip.sys driver. A specially crafted I/O request packet (IRP) can cause an arbitrary out-of-bounds read
