Full Report
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For Snort coverage that can detect
Analysis Summary
# Vulnerability: Adobe Photoshop Privilege Escalation
## CVE Details
- CVE ID: CVE-2026-48388
- CVSS Score: Not specified (High Severity)
- CWE: Not specified
## Affected Systems
- Products: Adobe Photoshop
- Versions: Photoshop_Set-Up.exe version 2.11.0.30
- Configurations: Installation functionality
## Vulnerability Description
A flaw exists in the installation functionality where an attacker can replace legitimate files with a specially crafted malformed file. During the execution of the installer, this leads to an escalation of privileges on the local system.
## Exploitation
- Status: Not exploited (Disclosed via coordinated disclosure)
- Complexity: Medium
- Attack Vector: Local
## Impact
- Confidentiality: High
- Integrity: High
- Availability: High
## Remediation
### Patches
- Adobe has released updates to address this vulnerability. Users should update to the latest version of the Photoshop installer.
## Detection
- Snort rules are available via Snort[.]org.
- Monitor for unauthorized file modifications in temporary installation directories.
## References
- hxxps://www[.]talosintelligence[.]com/vulnerability_reports/TALOS-2026-2360
---
# Vulnerability: Foxit Reader Arbitrary Code Execution
## CVE Details
- CVE ID: CVE-2026-57256, CVE-2026-91799
- CVSS Score: Not specified (Critical Severity)
- CWE: Use-After-Free (UAF)
## Affected Systems
- Products: Foxit Reader
- Versions: 2026.1.1.36485
- Configurations: Javascript checkbox CBF_Widget and Array object handling.
## Vulnerability Description
Two distinct flaws allow for code execution:
1. **CBF_Widget Flaw:** A malformed file triggers a vulnerability in the JavaScript checkbox functionality.
2. **Array Object UAF:** A use-after-free condition occurs when handling Array objects via JavaScript. A malicious PDF can trigger memory corruption.
## Exploitation
- Status: PoC available (Talos internal)
- Complexity: Low
- Attack Vector: Network (via malicious PDF)
## Impact
- Confidentiality: High
- Integrity: High
- Availability: High
## Remediation
### Patches
- Foxit has patched these vulnerabilities in recent updates. Users should update to the latest available version of Foxit Reader.
## Detection
- Indicators: Malicious JavaScript within PDF documents targeting `CBF_Widget` or `Array` objects.
- Snort coverage: Download latest rules from Snort[.]org.
## References
- hxxps://talosintelligence[.]com/vulnerability_reports/TALOS-2026-2420
- hxxps://talosintelligence[.]com/vulnerability_reports/TALOS-2026-2446
---
# Vulnerability: Microsoft Windows Kernel Driver Flaws
## CVE Details
- CVE ID: CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177
- CVSS Score: Not specified
- CWE: Out-of-bounds Read/Write, Use-After-Free, Type Confusion
## Affected Systems
- Products: Microsoft Windows (NETIO.sys, tcpip.sys, Cloud Files Mini Filter Driver)
- Versions: 10.0.26100.8457 and 10.0.26100.8655
- Configurations: Systems utilizing Cloud Filter APIs or specific I/O request packets (IRP).
## Vulnerability Description
Multiple vulnerabilities were found in Windows drivers:
- **NETIO.sys & tcpip.sys:** Out-of-bounds vulnerabilities triggered by specially crafted IRPs leading to information disclosure or Denial of Service (DoS).
- **cldflt.sys (Cloud Files):** Use-after-free and type confusion flaws triggered by specific API call sequences, leading to privilege escalation.
## Exploitation
- Status: Not exploited in the wild.
- Complexity: Medium to High.
- Attack Vector: Local (Requires execution of a dedicated application to trigger API/IRP calls).
## Impact
- Confidentiality: Medium to High
- Integrity: High (Privilege Escalation)
- Availability: Medium (DoS)
## Remediation
### Patches
- Microsoft has released security updates as part of their standard patch cycle. Apply the latest Windows Updates.
## Detection
- Monitor for unusual IRP activity or anomalous calls to the Cloud Filter API.
- Snort SID coverage available at Talos Intelligence.
## References
- hxxps://talosintelligence[.]com/vulnerability_reports/TALOS-2026-2443
- hxxps://talosintelligence[.]com/vulnerability_reports/TALOS-2026-2426
---
# Vulnerability: Apple macOS CoreWLAN Information Disclosure
## CVE Details
- CVE ID: Pending/Not explicitly listed in summary
- CVSS Score: Not specified
- CWE: Information Exposure
## Affected Systems
- Products: Apple macOS
- Versions: 26.3.1 (25D2128)
- Configurations: CoreWLAN functionality
## Vulnerability Description
An information disclosure vulnerability exists in the CoreWLAN framework. An attacker can trigger the flaw by calling a specific sequence of APIs, allowing for the unauthorized retrieval of system information.
## Exploitation
- Status: Not exploited
- Complexity: Medium
- Attack Vector: Local
## Impact
- Confidentiality: Medium
- Integrity: None
- Availability: None
## Remediation
### Patches
- Apple has patched this in macOS updates corresponding to the disclosure date.
## Detection
- Audit API call logs for CoreWLAN framework interactions.
## References
- hxxps://talosintelligence[.]com/vulnerability_reports/TALOS-2026-2376