Image: storage.ghost.io · rights & removal
Microsoft, Adobe, Apple, and Foxit vulnerabilities
Reporting by Talos Intelligence GroupRead the original at blog.talosintelligence.com
Executive Summary
Facts Only
TALOS-2026-2360 is a privilege escalation vulnerability in Photoshop's Installation functionality (PhotoshopSet-Up.exe version 2.11.0.30).
TALOS-2026-2376 is an information disclosure vulnerability in macOS CoreWLAN functionality (version(s): 26.3.1(25D2128).
TALOS-2026-2420 is a code execution vulnerability in Foxit Reader's Javascript checkbox CBFWidget functionality (version(s): 2026.1.1.36485).
TALOS-2026-2446 is a use-after-free vulnerability in Foxit Reader's Array object handling, leading to memory corruption and potential arbitrary code execution via malicious PDF documents.
TALOS-2026-2443 is an out-of-bounds pointer offset vulnerability in the Microsoft Windows NETIO.sys driver, allowing disclosure of sensitive information via crafted I/O request packets (IRPs).
TALOS-2026-2426 is a use-after-free vulnerability in the Windows Cloud Files Mini Filter Driver (version(s): 10.0.26100.8457 or WinBuild.160101.0800), potentially leading to privilege escalation through crafted API calls.
TALOS-2026-2445 is a type confusion vulnerability in the Windows Cloud Files Mini Filter Driver, exploitable via crafted API calls.
TALOS-2026-2427 is an out-of-bounds read vulnerability in the Microsoft Windows tcpip.sys driver, permitting arbitrary out-of-bounds reads in I/O request packets (IRPs).
Full Take
The landscape presented involves a coordinated disclosure of vulnerabilities across widely used applications and operating systems managed by multiple vendors. The pattern observed is a convergence of complex memory management flaws—use-after-free, out-of-bounds reads/writes, and type confusion—in core system drivers (Windows) and application functionality (Adobe, Foxit Reader, macOS). This suggests that the complexity inherent in modern software development, especially involving file handling and driver interactions, introduces systemic risk across different ecosystems simultaneously. The mechanism of disclosure via a third-party entity sets a baseline for community awareness, but the actual security exposure depends entirely on rapid patching cycles across diverse platforms. The implication is that vulnerabilities are not isolated technical bugs but symptoms of broader architectural challenges in secure coding practices applied to complex multi-layered software stacks.
BRIDGE QUESTIONS: What processes govern the cross-vendor identification and coordinated disclosure of such deeply embedded flaws? How does the reliance on third-party research as a primary source for threat intelligence influence risk prioritization when facing simultaneous, disparate exposures? What structural changes are necessary in development lifecycle management to mitigate these systemic risks at the source?
From the original · Talos Intelligence Group
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy.Read the full story at blog.talosintelligence.com
Sentinel — Human
This text appears to be a direct report of vulnerability disclosures, characterized by highly specific technical details and adherence to established disclosure protocols.
