Skip to content

Image: storage.ghost.io · rights & removal

Executive Summary

Cisco Talos disclosed vulnerabilities affecting Adobe, Apple, Foxit Reader, and Microsoft. These findings involved several specific issues across different software components, including privilege escalation in Photoshop, information disclosure in macOS CoreWLAN, code execution and use-after-free errors in Foxit Reader, and various memory and pointer-related vulnerabilities within the Microsoft Windows driver ecosystem. All disclosed vulnerabilities have been patched by the respective vendors following Cisco's third-party disclosure policy. Detection tools can utilize Snort rule sets, and advisories are available on the Talos Intelligence website.

Facts Only

TALOS-2026-2360 is a privilege escalation vulnerability in Photoshop's Installation functionality (PhotoshopSet-Up.exe version 2.11.0.30).
TALOS-2026-2376 is an information disclosure vulnerability in macOS CoreWLAN functionality (version(s): 26.3.1(25D2128).
TALOS-2026-2420 is a code execution vulnerability in Foxit Reader's Javascript checkbox CBFWidget functionality (version(s): 2026.1.1.36485).
TALOS-2026-2446 is a use-after-free vulnerability in Foxit Reader's Array object handling, leading to memory corruption and potential arbitrary code execution via malicious PDF documents.
TALOS-2026-2443 is an out-of-bounds pointer offset vulnerability in the Microsoft Windows NETIO.sys driver, allowing disclosure of sensitive information via crafted I/O request packets (IRPs).
TALOS-2026-2426 is a use-after-free vulnerability in the Windows Cloud Files Mini Filter Driver (version(s): 10.0.26100.8457 or WinBuild.160101.0800), potentially leading to privilege escalation through crafted API calls.
TALOS-2026-2445 is a type confusion vulnerability in the Windows Cloud Files Mini Filter Driver, exploitable via crafted API calls.
TALOS-2026-2427 is an out-of-bounds read vulnerability in the Microsoft Windows tcpip.sys driver, permitting arbitrary out-of-bounds reads in I/O request packets (IRPs).

Full Take

The landscape presented involves a coordinated disclosure of vulnerabilities across widely used applications and operating systems managed by multiple vendors. The pattern observed is a convergence of complex memory management flaws—use-after-free, out-of-bounds reads/writes, and type confusion—in core system drivers (Windows) and application functionality (Adobe, Foxit Reader, macOS). This suggests that the complexity inherent in modern software development, especially involving file handling and driver interactions, introduces systemic risk across different ecosystems simultaneously. The mechanism of disclosure via a third-party entity sets a baseline for community awareness, but the actual security exposure depends entirely on rapid patching cycles across diverse platforms. The implication is that vulnerabilities are not isolated technical bugs but symptoms of broader architectural challenges in secure coding practices applied to complex multi-layered software stacks.
BRIDGE QUESTIONS: What processes govern the cross-vendor identification and coordinated disclosure of such deeply embedded flaws? How does the reliance on third-party research as a primary source for threat intelligence influence risk prioritization when facing simultaneous, disparate exposures? What structural changes are necessary in development lifecycle management to mitigate these systemic risks at the source?

From the original · Talos Intelligence Group

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy.
Read the full story at blog.talosintelligence.com

Sentinel — Human

Confidence

This text appears to be a direct report of vulnerability disclosures, characterized by highly specific technical details and adherence to established disclosure protocols.

Signals Detected
low severity: Moderate sentence length variation; technical jargon presentation is direct but slightly repetitive in listing CVEs.
low severity: High coherence focused strictly on technical enumeration, lacking emotional inflection or broader contextual framing.
low severity: Strict adherence to a list/disclosure format; no flow or argumentative transition beyond simple factual statements.
low severity: The structure, referencing specific CVEs and vulnerability classes, suggests technical reporting rather than generalized synthesis. The structure mimics official security advisories.
Human Indicators
Use of specific internal references (Cisco Talos, CVE numbers) suggests an origin within the cybersecurity community or formal disclosure channels.
The tone is purely informational and directive, characteristic of security advisories.
Microsoft, Adobe, Apple, and Foxit vulnerabilities | Huntaegis