Patch Priorities for Adobe, Apple, Foxit and Windows
Cisco Talos details patched vulnerabilities across Photoshop, macOS, Foxit Reader and Windows, with practical guidance for prioritization and detection.
Security teams often evaluate vulnerabilities by product, vendor and severity. That approach can obscure the operational picture when several flaws affect software commonly installed across the same endpoint environment. Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe Photoshop, Apple macOS, Foxit Reader and Microsoft Windows. The affected products and vulnerability classes differ, but together they cover consequences ranging from information disclosure to arbitrary code execution and privilege escalation.
According to Cisco Talos, the vulnerabilities discussed in its roundup had been patched by the respective vendors in accordance with Cisco’s third-party vulnerability disclosure policy. The research does not describe a confirmed campaign, named threat actor, victim set or observed exploitation. It is a vendor-disclosed vulnerability analysis supported by Snort coverage, rather than an incident report. That distinction matters: the technical impact described below reflects the reported trigger conditions and potential consequences, not evidence that attackers chained these flaws in the wild.
What Cisco Talos reported
The roundup covers one Adobe Photoshop issue, one macOS CoreWLAN issue, two Foxit Reader flaws and four Microsoft Windows vulnerabilities. The affected components include an installer, a wireless networking framework, PDF JavaScript handling, file-system filter drivers and Windows networking drivers. Several issues require an attacker to provide a malformed file, invoke a specific API sequence or run a dedicated application.
The reported cases can be grouped into three practical risk categories:
- Code execution: The two Foxit Reader vulnerabilities can lead to arbitrary or remote code execution when a malicious PDF or crafted file reaches the vulnerable application.
- Privilege escalation: The Photoshop installation flaw and one Windows Cloud Files Mini Filter Driver issue can allow an attacker to elevate privileges under the conditions described by Talos.
- Information disclosure or availability impact: The macOS CoreWLAN issue and two Windows driver flaws involve information disclosure, while one Windows networking issue may also result in denial of service.
Adobe Photoshop: installer replacement and privilege escalation
TALOS-2026-2360, identified as CVE-2026-48388, affects the installation functionality of Photoshop. Cisco Talos lists Photoshop_Set-Up.exe version 2.11.0.30 as the affected version. The reported attack condition involves replacing files with a specially crafted malformed file. Under that condition, the vulnerability can lead to privilege escalation.
For administrators, the installer context is important. This is not described as a flaw in Photoshop’s image-processing functionality or as a malicious document issue. Instead, the reported weakness is associated with installation behavior and file handling. Organizations should therefore account for installer workflows, software distribution systems and endpoints where users or support personnel may execute installation packages.
The supplied research does not specify the required starting privileges, the exact file replacement mechanism, exploitation reliability or whether exploitation has been observed. It also does not identify a post-exploitation payload. Those details should not be inferred from the reported impact.
Apple macOS: CoreWLAN information disclosure
TALOS-2026-2376 concerns an information disclosure vulnerability in the CoreWLAN functionality of macOS. Cisco Talos lists macOS version 26.3.1 (25D2128) as affected and says an attacker can trigger the issue by calling a sequence of APIs.
The report does not state what information could be disclosed, whether user interaction is needed, or what level of local or remote access is required before the API sequence can be used. Consequently, defenders should treat this as a confirmed information-disclosure finding, while leaving the scope and sensitivity of the exposed data to vendor documentation and testing of the relevant update.
Mac administrators should include CoreWLAN in their review of operating-system updates, particularly where wireless connectivity is central to employee access, shared workspaces or managed fleets. The research does not establish that wireless networks themselves are the delivery mechanism, and it should not be interpreted as evidence of a network-based exploit.
Foxit Reader: malicious PDFs and JavaScript processing
The two Foxit Reader findings present the clearest document-delivery risk in the roundup. TALOS-2026-2420, CVE-2026-57256, is a code execution vulnerability in the JavaScript checkbox CBF_Widget functionality of Foxit Reader version 2026.1.1.36485. Cisco Talos reports that a specially crafted malformed file provided by an attacker can lead to remote code execution.
TALOS-2026-2446, CVE-2026-91799, is a use-after-free vulnerability involving Foxit Reader’s handling of an Array object. In this case, specially crafted JavaScript inside a malicious PDF can trigger memory corruption and result in arbitrary code execution.
These findings make PDF intake and reader configuration relevant parts of patch planning. Organizations should identify where Foxit Reader is deployed, determine whether PDF JavaScript is required for business processes, and apply the vendor’s security update. Email security, web gateways and endpoint telemetry can also help security teams investigate unusual PDF delivery or suspicious reader-child-process activity, but the supplied research does not define a particular process chain, exploit signature or confirmed campaign.
The distinction between the two Foxit issues is also useful for technical teams. One is tied to the JavaScript checkbox CBF_Widget functionality and a malformed file; the other involves JavaScript in a malicious PDF, an Array object and memory corruption. Both are associated with code execution, but the report does not say that they can be combined or that one is a prerequisite for the other.
Microsoft Windows: drivers, Cloud Files and networking
Cisco Talos identifies four Windows vulnerabilities across system drivers and the Cloud Files Mini Filter Driver.
TALOS-2026-2443, CVE-2026-50475, is an out-of-bounds pointer offset vulnerability in the Windows NETIO.sys driver. A specially crafted I/O request packet can cause disclosure of sensitive information, according to the report. The research does not define the data exposed or the access needed to submit the request.
TALOS-2026-2426, CVE-2026-58613, is a use-after-free vulnerability in the Windows Cloud Files Mini Filter Driver. The affected version is listed as 10.0.26100.8457 (WinBuild.160101.0800). Cisco Talos says a specially crafted sequence of Cloud Filter API calls, executed with a dedicated application, can lead to privilege escalation.
TALOS-2026-2445, CVE-2026-80093, is a type confusion vulnerability in the same Windows Cloud Files Mini Filter Driver. The listed affected versions are 10.0.26100.8457 and 10.0.26100.8655, both marked with the same WinBuild identifier. A specially crafted sequence of Cloud Filter API calls can cause type confusion, and an attacker can execute a dedicated application to trigger the issue. The supplied report does not assign a specific impact beyond the type confusion condition.
Finally, TALOS-2026-2427, CVE-2026-49177, affects the Windows tcpip.sys driver. Cisco Talos describes an out-of-bounds read triggered by a specially crafted I/O request packet. The potential outcomes are information disclosure or a denial-of-service condition.
These Windows findings should not be treated as a single exploit chain. They affect different components and have different trigger conditions. The roundup does not report chained exploitation, remote exploitation, malware deployment or a method for moving from information disclosure to privilege escalation. Patch management teams should prioritize according to asset exposure, business importance and the availability of the vendor fixes rather than assume that all four issues have the same operational risk.
Detection and defensive use of Snort coverage
Cisco Talos says Snort coverage is available for detecting exploitation of the vulnerabilities and directs users to download the latest rule sets from Snort.org. The supplied research does not provide individual rule identifiers, packet patterns or validated detection logic. Teams should therefore obtain the current rules directly from the referenced Snort distribution and verify that the rules are enabled, supported by the deployed Snort version and monitored for actionable alerts.
Network detection should complement, not replace, remediation. Some reported conditions involve local APIs, dedicated applications, installer file handling or malformed documents, which may not be visible as a distinctive network event. Useful defensive telemetry includes endpoint software inventories, operating-system and application version data, installer execution records, PDF-reader process activity, application-crash reports, privilege changes and relevant Windows driver or application logs. macOS administrators should likewise retain update and endpoint telemetry sufficient to identify systems running the affected CoreWLAN version.
Alert triage should preserve the distinction between evidence of a vulnerability trigger and evidence of successful compromise. A Snort alert may indicate traffic associated with an exploit attempt, while endpoint telemetry is needed to determine whether code execution, privilege escalation, information disclosure or service disruption followed. The research does not provide indicators of compromise, so organizations should not expect a fixed list of domains, IP addresses, files or hashes from this report.
What organizations should do now
- Inventory affected software and versions. Identify Photoshop installations, Foxit Reader deployments, managed macOS systems and Windows endpoints containing the listed affected components or versions.
- Apply vendor patches. Cisco Talos states that the vulnerabilities were patched by the respective vendors. Use the applicable vendor updates and confirm successful installation rather than relying only on deployment status.
- Prioritize code-execution exposure. Give urgent attention to Foxit Reader systems that open external PDFs or process untrusted documents, while also addressing the Photoshop privilege-escalation issue and the Windows Cloud Files findings.
- Reduce document attack surface where practical. Review whether Foxit Reader PDF JavaScript is necessary for business operations and use organizational controls that limit untrusted document execution or isolate high-risk document handling.
- Deploy and review Snort coverage. Download current rules from Snort.org, validate compatibility and investigate alerts alongside endpoint evidence.
- Hunt for exploitation signals without overclaiming. Review suspicious malformed documents, unexpected reader behavior, unusual installer activity, privilege changes and relevant driver or application errors. The research supplies no confirmed victims or campaign-specific indicators.
- Document residual exposure. Track systems that cannot be patched, record compensating controls and reassess them after software updates or configuration changes.
Conclusion
Cisco Talos’ roundup provides a concrete patching agenda across endpoint applications and operating-system components. The most direct execution risks concern Foxit Reader’s handling of crafted PDF content, while Adobe Photoshop and Windows Cloud Files issues involve privilege escalation. macOS CoreWLAN and Windows networking flaws add information-disclosure and availability considerations. No confirmed campaign or attacker attribution is reported. Organizations should use the findings to drive version-based remediation, targeted document and endpoint monitoring, and carefully validated Snort coverage.
Sources
Cisco Talos: Microsoft, Adobe, Apple, and Foxit vulnerabilities