- Cisco Talos disclosed eight patched flaws in Foxit Reader, a Photoshop installer, macOS and Windows drivers. The post reports no exploitation in the wild.
- The flaws sit at different steps of an attack, from opening a file to gaining higher access on a machine.
- Confirm each product is on its vendor's current patched release, including laptops outside central management.
Most security reports focus on the server. This one is about the laptop on an employee's desk. Cisco Talos has published details of eight vulnerabilities, now patched. They affect desktop software: a PDF reader, an image editor's installer, macOS and the Windows networking and file drivers.
The lesson here is that a desktop is not one door. It is several, and a flaw in one can hand an attacker the key to the next.
What Talos disclosed
Talos' vulnerability research team disclosed the flaws. The vendors have patched them under Cisco's third-party disclosure policy. The post does not say any of them were exploited in the wild. It also gives no severity scores.
Two affect Foxit Reader. One is CVE-2026-57256, in the reader's JavaScript checkbox code, in version 2026.1.1.36485. Talos says a specially crafted malformed file can lead to remote code execution. The other is CVE-2026-91799, a use-after-free flaw in how Foxit handles an Array object. Talos says JavaScript inside a malicious PDF can trigger it.
Another flaw is in the Adobe Photoshop setup program. Tracked as CVE-2026-48388, it affects the installer file Photoshop_Set-Up.exe at version 2.11.0.30. Talos says an attacker who replaces files with a specially crafted malformed one can gain higher privileges.
One affects macOS 26.3.1: TALOS-2026-2376, an information disclosure flaw in CoreWLAN, triggered by a sequence of API calls. The post gives that one no CVE ID.
How these flaws work
A use-after-free bug happens when a program keeps using a piece of memory after it has handed it back. Talos says the crafted JavaScript in Foxit Reader can lead to memory corruption and arbitrary code execution. In general, a use-after-free lets an attacker who controls what lands in that memory steer the program.
The Windows flaws are of a different kind. Four sit in drivers, the low-level components that handle networking and files. CVE-2026-50475 in NETIO.sys and CVE-2026-49177 in tcpip.sys involve specially crafted I/O request packets. The first can disclose sensitive information. The second is an out-of-bounds read that can disclose information or cause a denial of service.
The other two are in the Windows Cloud Files Mini Filter Driver. CVE-2026-58613 is the same memory-reuse error described above, and Talos says it can lead to privilege escalation. CVE-2026-80093 is a type confusion flaw, where the code treats data as the wrong kind of object. Talos says both are triggered by a dedicated application that makes Cloud Filter API calls in a crafted sequence.
Why the layers matter
These flaws sit at different steps of an attack. The Foxit bugs start from a file someone opens. The Photoshop installer flaw and one Cloud Files flaw raise privileges. Because the Cloud Files bugs need a dedicated application, we infer that an attacker would already need to run code on the machine. Talos does not state that point.
Talos does not say anyone combined these flaws. But the pattern deserves a manager's attention. A document that runs code is a first step. A driver flaw that raises privileges is a later one. Each layer you leave unpatched shortens the path.
This also shows where risk can hide in an asset list. Teams track the main PDF viewer closely. A second reader, an installer left on disk or an unmanaged Mac is easier to miss. Those are the products named here.
Questions for your security team
First, ask which of these products run on company machines, including Foxit Reader, Photoshop and macOS. The post does not name the fixed versions, so ask the team to confirm each is on the vendor's current patched release. Check the vulnerable builds Talos lists: Foxit 2026.1.1.36485, Photoshop installer 2.11.0.30, macOS 26.3.1 and Cloud Files Mini Filter Driver builds 10.0.26100.8457 and 10.0.26100.8655.
Second, ask whether PDF JavaScript is needed at all. Talos describes CVE-2026-91799 as triggered by JavaScript in a malicious PDF, so turning JavaScript off may reduce exposure. It is no substitute for patching. The source does not confirm that it blocks the checkbox flaw, CVE-2026-57256.
Third, ask whether laptops outside central management receive Windows and macOS updates on the same schedule as the rest.
Talos also points to Snort rule sets that can detect exploitation of these flaws. Ask whether your network monitoring uses the latest rules.
A patched flaw costs little. An unpatched one on an overlooked machine can cost much more. The way to reduce that risk is a complete list of what is installed.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Cisco Talos.





