Threat reportVulnerabilityTL-2026-3011
Cisco Talos disclosure: Microsoft, Adobe, Apple, and Foxit vulnerabilities (CVE-2026-48388, CVE-2026-57256, CVE-2026-91799, CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177)
Cisco Talos disclosure (TL-2026-3011), also tracked as TALOS-2026-2360, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-10-07. It has no confirmed attribution, affects Adobe Photoshop installer (Photoshop_Set-Up.exe), references 7 CVEs (CVE-2026-48388, CVE-2026-57256, CVE-2026-91799), maps to 5 MITRE ATT&CK techniques (T1005, T1059.007, T1203), and is covered by 9 detection rules and 5 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 7Referenced vulnerabilities
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 5Indicators of compromise
Key facts for TL-2026-3011
- Threat ID
- TL-2026-3011
- Also known as
- TALOS-2026-2360, TALOS-2026-2376, TALOS-2026-2420, TALOS-2026-2426, TALOS-2026-2427, TALOS-2026-2443
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, enterprise, government administration, finance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 5
How Cisco Talos disclosure works
Cisco Talos published a roundup of eight patched vulnerabilities it discovered: an Adobe Photoshop installer privilege escalation, an Apple macOS CoreWLAN location-history information disclosure (no CVE), two Foxit Reader JavaScript use-after-free code-execution flaws, and four Windows kernel-driver flaws (NETIO.sys, tcpip.sys, and two in the Cloud Files Mini Filter). None is reported as exploited in the wild.
Cisco Talos (Kri Dontje) published a vulnerability roundup on 2026-10-07 covering eight issues found by Talos researchers (KPC, Marcin 'Icewall' Noga, Francesco Benvenuto). All have vendor fixes available.
Adobe Photoshop (CVE-2026-48388, TALOS-2026-2360, CVSS 8.2, CWE-427): the elevated installer Photoshop_Set-Up.exe 2.11.0.30 looks for 'Adobe Installer.exe' in the user-writable %TEMP%\winget\ directory before the legitimate program directory. A standard user who plants a file there gets code execution at high integrity, potentially SYSTEM. Fixed by Adobe on 2026-07-28.
Foxit Reader 2026.1.1.36485 has two JavaScript use-after-free flaws (both CVSS 7.8, CWE-416). CVE-2026-57256 (TALOS-2026-2420) is in the checkbox CBF_Widget functionality: the PoC calls resetForm() and deletePages() to free form-field array objects that are then accessed. CVE-2026-91799 (TALOS-2026-2446) is a use-after-free in Array object handling reachable through the resetForm method. Both need the victim to open a crafted PDF. Fixed in Foxit PDF Reader/Editor 2026.1.2 (July 2026) and 2026.2.1 (September 2026).
Windows Cloud Files Mini Filter Driver (build 10.0.26100.8457 and 10.0.26100.8655): CVE-2026-58613 (TALOS-2026-2426, CVSS 8.8, CWE-416) is a use-after-free in CldiStreamCompleteRequest. A sync provider that terminates without disconnecting leaves orphaned requests on a global countdown timer list, and the timer cleanup frees a request that is still referenced. CVE-2026-80093 (TALOS-2026-2445, CVSS 8.8, CWE-843) is a type confusion in CldiStreamPrepareRequestForMoreProcessing. A race between CldStreamAbortOperation and a stack-based LIST_ENTRY sentinel makes the abort walker treat the sentinel as a request object, giving writes through a fake request pointer into another thread's kernel stack. Exploitation needs a registered sync provider, dehydrated placeholders, fetch-data callbacks, and the undocumented CfAbortOperation API timed against CfDisconnectSyncRoot. Both are local privilege escalations.
Two Windows information-disclosure bugs are reached through IRPs to IOCTL 0x120007. CVE-2026-50475 (TALOS-2026-2443, CVSS 5.5, CWE-823) is an off-by-one in NETIO.sys NsipGetAllInformationProviderParameters (the TableIndex check uses <= instead of <), which leaks 16 bytes of kernel data including tcpip.sys function pointers and so defeats ASLR. CVE-2026-49177 (TALOS-2026-2427, CVSS 8.4, CWE-125) is an out-of-bounds read in tcpip.sys IppQualifyAddresses when MaxDestCount exceeds 0x1f4, with a 0x1c-byte stride per iteration; it can cause information disclosure or denial of service. Microsoft patched both on 2026-07-14.
Apple macOS 26.3.1 (25D2128) CoreWLAN (TALOS-2026-2376, no CVE, CVSS 3.3, CWE-912): a low-privilege local process can read undocumented CWNetworkProfile properties (lastConnected, bssidList with latitude, longitude, accuracy and timestamps) and rebuild the device's location history without special permissions. Apple addressed it as defense-in-depth in macOS 27 (disclosed 2026-09-14).
The Talos page does not state in-the-wild exploitation. Search results indicate CVE-2026-58613 is not listed in CISA KEV, and no public exploitation was found for the others. These are patch-prioritization items; the kernel privilege-escalation and information-disclosure bugs are the sort that can be chained after initial access.
MITRE ATT&CK techniques used in TL-2026-3011
Collection
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File
Defense Evasion
T1574.008 Hijack Execution Flow: Path Interception by Search Order Hijacking
Affected products and versions in Cisco Talos disclosure
- Adobe — Photoshop installer (Photoshop_Set-Up.exe)
Vulnerable versions: 2.11.0.30
Fixed in: Adobe update released 2026-07-28 - Foxit — Foxit Reader / PDF Reader
Vulnerable versions: 2026.1.1.36485
Fixed in: 2026.1.2 (CVE-2026-57256); 2026.2.1 (CVE-2026-91799) - Microsoft — Windows Cloud Files Mini Filter Driver
Vulnerable versions: 10.0.26100.8457; 10.0.26100.8655 (CVE-2026-80093)
Fixed in: 2026-07-14 update (CVE-2026-58613); 2026-09-08 update (CVE-2026-80093) - Microsoft — Windows NETIO.sys
Vulnerable versions: 10.0.26100.8457
Fixed in: 2026-07-14 update - Microsoft — Windows TCP/IP driver (tcpip.sys)
Vulnerable versions: 10.0.26100.8457
Fixed in: 2026-07-14 update - Apple — macOS CoreWLAN
Vulnerable versions: 26.3.1 (25D2128)
Fixed in: macOS 27
Remediation for Cisco Talos disclosure
Patches
- Microsoft MSRC: CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177
- Foxit PDF Reader/Editor 2026.1.2 (CVE-2026-57256) and 2026.2.1 (CVE-2026-91799)
- Adobe Photoshop update of 2026-07-28 (CVE-2026-48388)
- macOS 27 (TALOS-2026-2376)
Immediate actions
- Apply the July 14, 2026 Microsoft security updates (NETIO.sys, tcpip.sys, Cloud Files Mini Filter) and the September 8, 2026 update for CVE-2026-80093
- Update Foxit PDF Reader/Editor to 2026.2.1 or later (14.0.8 / 13.2.7 for PDF Editor)
- Update Adobe Photoshop to the build released 2026-07-28 or later
Workarounds
- Disable JavaScript in Foxit Reader and open untrusted PDFs in a sandbox or Protected View until updated
- Do not run Adobe installers from user-writable working directories on shared systems
Longer-term hardening
- Restrict standard users from writing to %TEMP% paths used by elevated installers where feasible
- Monitor for unusual Cloud Filter API use by non-sync-provider processes
- Upgrade macOS to version 27
CVEs associated with Cisco Talos disclosure
CVE-2026-48388, CVE-2026-57256, CVE-2026-91799, CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177
Weaknesses (CWE) in Cisco Talos disclosure
Timeline of Cisco Talos disclosure
- Talos contacts Apple about the macOS CoreWLAN information disclosure (TALOS-2026-2376)
- Photoshop installer privilege escalation (CVE-2026-48388) reported to Adobe
- Foxit Reader CBF_Widget use-after-free (CVE-2026-57256) reported to Foxit
- Cloud Files Mini Filter use-after-free (CVE-2026-58613) and tcpip.sys out-of-bounds read (CVE-2026-49177) disclosed to Microsoft
- NETIO.sys (CVE-2026-50475) and Cloud Files Mini Filter type confusion (CVE-2026-80093) reported to Microsoft
- Foxit Reader Array use-after-free (CVE-2026-91799) disclosed to Foxit
- Foxit releases fixes including CVE-2026-57256 (Reader/Editor 2026.1.2)
- Microsoft patches CVE-2026-50475, CVE-2026-58613 and CVE-2026-49177
- Adobe patches Photoshop installer CVE-2026-48388
- Microsoft patches Cloud Files Mini Filter type confusion CVE-2026-80093
- Apple addresses CoreWLAN disclosure in macOS 27 and TALOS-2026-2376 goes public
- Foxit releases fix for CVE-2026-91799 (Reader/Editor 2026.2.1)
- Cisco Talos publishes the vulnerability roundup covering all eight issues
Sources cited for Cisco Talos disclosure
- Microsoft, Adobe, Apple, and Foxit vulnerabilities (Cisco Talos)
- TALOS-2026-2360 Adobe Photoshop installer privilege escalation
- TALOS-2026-2376 Apple macOS CoreWLAN information disclosure
- TALOS-2026-2420 Foxit Reader CBF_Widget use-after-free
- TALOS-2026-2446 Foxit Reader Array use-after-free
- TALOS-2026-2443 Windows NETIO.sys information disclosure
- TALOS-2026-2426 Windows Cloud Files Mini Filter use-after-free
- TALOS-2026-2445 Windows Cloud Files Mini Filter type confusion
- TALOS-2026-2427 Windows tcpip.sys out-of-bounds read
- Foxit Security Bulletins
- MSRC CVE-2026-58613
- MSRC CVE-2026-80093
- MSRC CVE-2026-50475
- NVD CVE-2026-58613
- macOS 27 Release Notes
Detection coverage for TL-2026-3011
As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3011 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.