Security1 publisherNot yet confirmed elsewhere2 min readPublished
Talos discloses eight patched flaws, including two Foxit Reader code-execution bugs
Cisco Talos disclosed eight vendor-patched flaws in Foxit Reader, Windows, Photoshop's installer and macOS CoreWLAN. The two Foxit Reader bugs reach code execution from an attacker's file, so Reader is the update to confirm on endpoints first.
The Watch · Security desk

What happened
- A use-after-free in the Windows Cloud Files Mini Filter Driver, CVE-2026-58613, lets a dedicated application escalate privileges with a crafted sequence of Cloud Filter API calls.
- Photoshop's flaw, CVE-2026-48388, is in the setup program Photoshop_Set-Up.exe 2.11.0.30 and grants privilege escalation when an attacker replaces files with a malformed one.
- Out-of-bounds bugs in the NETIO.sys and tcpip.sys drivers leak information when sent a crafted I/O request packet, and the tcpip.sys flaw can also cause a denial of service.
- Apple's CoreWLAN flaw on macOS 26.3.1 discloses information to code that calls a sequence of APIs, and Talos lists it as TALOS-2026-2376 without a CVE number.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Windows endpoints with an unpatched Reader hold both stages an intruder needs: code execution from a document, then privilege escalation through the Cloud Files driver on the same host.
- constraint A build-number check against Talos's list cannot clear a Windows host, because the Cloud Files type confusion, CVE-2026-80093, was still present in driver build 10.0.26100.8655.
- decision The Photoshop fix has to reach software distribution shares and build images, since a stored copy of the 2.11.0.30 setup file can be redeployed after endpoints are updated.
Foxit Reader is the entry point in this batch. According to Talos, CVE-2026-57256 is in the JavaScript checkbox widget code (CBF_Widget) of Foxit Reader 2026.1.1.36485, and a malformed file supplied by an attacker leads to remote code execution [6]. CVE-2026-91799 is a use-after-free in Reader's handling of Array objects. JavaScript inside a malicious PDF triggers it, corrupting memory and allowing arbitrary code execution [7].
The other six bugs need attacker activity on the target first: files replaced in the Photoshop installer, an API call sequence on macOS, a dedicated application on Windows, or crafted I/O request packets sent to a kernel driver [13]. The three information-disclosure bugs in CoreWLAN, NETIO.sys and tcpip.sys rate lowest. Each one hands data to code an attacker already has running [5][8][11].
The Cloud Files pair rates higher. CVE-2026-58613 gives privilege escalation outright [9]. Its sibling, CVE-2026-80093, is a type confusion that Talos describes only as type confusion, with no stated end result [10].
Checking rollout against this post takes a second source. Talos lists the builds it tested [4][6][9]. The post does not give fixed version numbers, name an attacker, or say whether any of the bugs has been exploited. Teams need each vendor's own advisory to know which build counts as patched.
Talos published the eight under Cisco's third-party vulnerability disclosure policy, after each vendor had patched [12][2]. The exposure is the time between those vendor releases and a team's own deployment. For that period, Talos points to its latest Snort rule sets, downloadable from Snort.org, for detecting exploitation [3].
What to watch
- Foxit's advisory naming the fixed Reader build for CVE-2026-57256 and CVE-2026-91799, the version endpoints need to be checked against.
- Any report of the Foxit or Cloud Files bugs being used in attacks; that would move them from routine patch work to incident response.
- Apple publishing a CVE number for the CoreWLAN flaw, TALOS-2026-2376, in its security notes.