Cisco Talos's Vulnerability Discovery & Research team has recently disclosed a series of vulnerabilities affecting products from Microsoft, Adobe, Apple, and Foxit. All identified vulnerabilities have reportedly been patched by their respective vendors, aligning with Cisco's responsible disclosure policies. The issues range from privilege escalation and information disclosure to remote code execution and denial-of-service conditions.
Adobe Photoshop was found to have a privilege escalation vulnerability, tracked as TALOS-2026-2360 (CVE-2026-48388). This flaw exists in the installation functionality of Photoshop_Set-Up.exe, specifically version 2.11.0.30. An attacker could exploit this by replacing legitimate files with a specially crafted, malformed file during installation, leading to elevated privileges.
Apple's macOS operating system contained an information disclosure vulnerability, identified as TALOS-2026-2376, within its CoreWLAN functionality. This issue affected macOS version 26.3.1(25D2128). Exploitation could occur if an attacker called a specific sequence of APIs, potentially revealing sensitive information.
Foxit Reader was impacted by two distinct vulnerabilities. TALOS-2026-2420 (CVE-2026-57256) is a code execution vulnerability found in the Javascript checkbox CBF_Widget functionality of Foxit Reader version 2026.1.1.36485. A specially crafted malicious file could trigger this flaw, enabling remote code execution. The second, TALOS-2026-2446 (CVE-2026-91799), is a use-after-free vulnerability related to how Foxit Reader processes Array objects. This could be exploited via specially crafted JavaScript embedded in a malicious PDF document, leading to memory corruption and arbitrary code execution.
Microsoft Windows drivers and components were subject to multiple vulnerabilities. TALOS-2026-2443 (CVE-2026-50475) is an out-of-bounds pointer offset vulnerability in the NETIO.sys driver. A specially crafted I/O request packet (IRP) could lead to the disclosure of sensitive information.
Two vulnerabilities were identified in the Windows Cloud Files Mini Filter Driver. TALOS-2026-2426 (CVE-2026-58613) is a use-after-free vulnerability affecting version 10.0.26100.8457 (WinBuild.160101.0800). An attacker could achieve privilege escalation by executing a dedicated application that makes a specially crafted sequence of Cloud Filter API calls.
The second Cloud Files Mini Filter Driver vulnerability, TALOS-2026-2445 (CVE-2026-80093), is a type confusion flaw. This affected versions 10.0.26100.8457 (WinBuild.160101.0800) and 10.0.26100.8655 (WinBuild.160101.0800). Similar to the use-after-free vulnerability, an attacker could trigger this by executing a dedicated application that makes a specially crafted sequence of Cloud Filter API calls, leading to type confusion.
Finally, TALOS-2026-2427 (CVE-2026-49177) is an out-of-bounds read vulnerability discovered in the Microsoft Windows tcpip.sys driver. Exploiting this flaw with a specially crafted I/O request packet (IRP) could result in an arbitrary out-of-bounds read, potentially causing information disclosure or a denial-of-service condition.






