Cisco Talos Details Multiple Vulnerabilities in Adobe, Apple, Foxit, and Microsoft Products
Cisco Talos has disclosed several vulnerabilities affecting Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows, with vendors having already released patches.

Cisco Talos' Vulnerability Discovery & Research team has announced the discovery and subsequent disclosure of multiple vulnerabilities impacting widely used software from Adobe, Apple, Foxit, and Microsoft. These vulnerabilities, which span various types including privilege escalation, code execution, information disclosure, and type confusion, have been addressed by the respective vendors through released patches, adhering to Cisco's third-party vulnerability disclosure policy.
The vulnerabilities identified include an Adobe Photoshop privilege escalation flaw (CVE-2026-48388, TALOS-2026-2360) within its installation functionality. An attacker could exploit this by replacing files with a specially crafted malicious file, leading to elevated privileges on the affected system. For users of Apple's macOS, an information disclosure vulnerability (TALOS-2026-2376) was found in the CoreWLAN functionality. This flaw can be triggered by an attacker through a sequence of API calls, potentially exposing sensitive system information.
Foxit Reader is affected by two distinct vulnerabilities. TALOS-2026-2420 (CVE-2026-57256) is a code execution vulnerability in the Javascript checkbox functionality. Exploitation requires an attacker to provide a specially crafted malformed file, which could lead to remote code execution. Additionally, TALOS-2026-2446 (CVE-2026-91799) is a use-after-free vulnerability related to how Foxit Reader handles Array objects. A malicious PDF document containing crafted JavaScript could trigger this, resulting in memory corruption and potential arbitrary code execution.
Microsoft Windows is impacted by a series of vulnerabilities across different components. The NETIO.sys driver has an out-of-bounds pointer offset vulnerability (TALOS-2026-2443, CVE-2026-50475) that could lead to the disclosure of sensitive information via specially crafted I/O request packets (IRPs). Furthermore, the Cloud Files Mini Filter Driver is affected by a use-after-free vulnerability (TALOS-2026-2426, CVE-2026-58613) and a type confusion vulnerability (TALOS-2026-2445, CVE-2026-80093). These flaws, exploitable through specific Cloud Filter API call sequences, can lead to privilege escalation or type confusion, respectively.
Another vulnerability affecting Microsoft Windows is an out-of-bounds read in the tcpip.sys driver (TALOS-2026-2427, CVE-2026-49177). This vulnerability, triggered by a specially crafted IRP, could allow an attacker to perform an arbitrary out-of-bounds read, potentially resulting in information disclosure or a denial-of-service condition.
Cisco Talos emphasizes that all disclosed vulnerabilities have been patched by the vendors. For organizations using Snort, specific rule sets are available on Snort.org to detect exploitation attempts. The full details of Talos' vulnerability advisories are consistently posted on the Talos Intelligence website, providing security professionals with the necessary information to protect their networks.
This coordinated disclosure highlights the ongoing efforts by security researchers to identify and report vulnerabilities in widely used software. The swift patching by vendors underscores the importance of timely updates and robust vulnerability management practices for end-users to mitigate potential risks.