Threat reportVulnerabilityTL-2026-3011

Cisco Talos disclosure: Microsoft, Adobe, Apple, and Foxit vulnerabilities (CVE-2026-48388, CVE-2026-57256, CVE-2026-91799, CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177)

highPATCHED

Cisco Talos disclosure (TL-2026-3011), also tracked as TALOS-2026-2360, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-10-07. It has no confirmed attribution, affects Adobe Photoshop installer (Photoshop_Set-Up.exe), references 7 CVEs (CVE-2026-48388, CVE-2026-57256, CVE-2026-91799), maps to 5 MITRE ATT&CK techniques (T1005, T1059.007, T1203), and is covered by 9 detection rules and 5 indicators of compromise.

CVSS
8.8/10High
CVEs
7Referenced vulnerabilities
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
5Indicators of compromise

Key facts for TL-2026-3011

Threat ID
TL-2026-3011
Also known as
TALOS-2026-2360, TALOS-2026-2376, TALOS-2026-2420, TALOS-2026-2426, TALOS-2026-2427, TALOS-2026-2443
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, enterprise, government administration, finance
Target regions
Global
Detection rules
9
Indicators of compromise
5

How Cisco Talos disclosure works

Cisco Talos published a roundup of eight patched vulnerabilities it discovered: an Adobe Photoshop installer privilege escalation, an Apple macOS CoreWLAN location-history information disclosure (no CVE), two Foxit Reader JavaScript use-after-free code-execution flaws, and four Windows kernel-driver flaws (NETIO.sys, tcpip.sys, and two in the Cloud Files Mini Filter). None is reported as exploited in the wild.

Cisco Talos (Kri Dontje) published a vulnerability roundup on 2026-10-07 covering eight issues found by Talos researchers (KPC, Marcin 'Icewall' Noga, Francesco Benvenuto). All have vendor fixes available.

Adobe Photoshop (CVE-2026-48388, TALOS-2026-2360, CVSS 8.2, CWE-427): the elevated installer Photoshop_Set-Up.exe 2.11.0.30 looks for 'Adobe Installer.exe' in the user-writable %TEMP%\winget\ directory before the legitimate program directory. A standard user who plants a file there gets code execution at high integrity, potentially SYSTEM. Fixed by Adobe on 2026-07-28.

Foxit Reader 2026.1.1.36485 has two JavaScript use-after-free flaws (both CVSS 7.8, CWE-416). CVE-2026-57256 (TALOS-2026-2420) is in the checkbox CBF_Widget functionality: the PoC calls resetForm() and deletePages() to free form-field array objects that are then accessed. CVE-2026-91799 (TALOS-2026-2446) is a use-after-free in Array object handling reachable through the resetForm method. Both need the victim to open a crafted PDF. Fixed in Foxit PDF Reader/Editor 2026.1.2 (July 2026) and 2026.2.1 (September 2026).

Windows Cloud Files Mini Filter Driver (build 10.0.26100.8457 and 10.0.26100.8655): CVE-2026-58613 (TALOS-2026-2426, CVSS 8.8, CWE-416) is a use-after-free in CldiStreamCompleteRequest. A sync provider that terminates without disconnecting leaves orphaned requests on a global countdown timer list, and the timer cleanup frees a request that is still referenced. CVE-2026-80093 (TALOS-2026-2445, CVSS 8.8, CWE-843) is a type confusion in CldiStreamPrepareRequestForMoreProcessing. A race between CldStreamAbortOperation and a stack-based LIST_ENTRY sentinel makes the abort walker treat the sentinel as a request object, giving writes through a fake request pointer into another thread's kernel stack. Exploitation needs a registered sync provider, dehydrated placeholders, fetch-data callbacks, and the undocumented CfAbortOperation API timed against CfDisconnectSyncRoot. Both are local privilege escalations.

Two Windows information-disclosure bugs are reached through IRPs to IOCTL 0x120007. CVE-2026-50475 (TALOS-2026-2443, CVSS 5.5, CWE-823) is an off-by-one in NETIO.sys NsipGetAllInformationProviderParameters (the TableIndex check uses <= instead of <), which leaks 16 bytes of kernel data including tcpip.sys function pointers and so defeats ASLR. CVE-2026-49177 (TALOS-2026-2427, CVSS 8.4, CWE-125) is an out-of-bounds read in tcpip.sys IppQualifyAddresses when MaxDestCount exceeds 0x1f4, with a 0x1c-byte stride per iteration; it can cause information disclosure or denial of service. Microsoft patched both on 2026-07-14.

Apple macOS 26.3.1 (25D2128) CoreWLAN (TALOS-2026-2376, no CVE, CVSS 3.3, CWE-912): a low-privilege local process can read undocumented CWNetworkProfile properties (lastConnected, bssidList with latitude, longitude, accuracy and timestamps) and rebuild the device's location history without special permissions. Apple addressed it as defense-in-depth in macOS 27 (disclosed 2026-09-14).

The Talos page does not state in-the-wild exploitation. Search results indicate CVE-2026-58613 is not listed in CISA KEV, and no public exploitation was found for the others. These are patch-prioritization items; the kernel privilege-escalation and information-disclosure bugs are the sort that can be chained after initial access.

MITRE ATT&CK techniques used in TL-2026-3011

Collection

T1005 Data from Local System

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File

Defense Evasion

T1574.008 Hijack Execution Flow: Path Interception by Search Order Hijacking

Affected products and versions in Cisco Talos disclosure

  • Adobe — Photoshop installer (Photoshop_Set-Up.exe)
    Vulnerable versions: 2.11.0.30
    Fixed in: Adobe update released 2026-07-28
  • Foxit — Foxit Reader / PDF Reader
    Vulnerable versions: 2026.1.1.36485
    Fixed in: 2026.1.2 (CVE-2026-57256); 2026.2.1 (CVE-2026-91799)
  • Microsoft — Windows Cloud Files Mini Filter Driver
    Vulnerable versions: 10.0.26100.8457; 10.0.26100.8655 (CVE-2026-80093)
    Fixed in: 2026-07-14 update (CVE-2026-58613); 2026-09-08 update (CVE-2026-80093)
  • Microsoft — Windows NETIO.sys
    Vulnerable versions: 10.0.26100.8457
    Fixed in: 2026-07-14 update
  • Microsoft — Windows TCP/IP driver (tcpip.sys)
    Vulnerable versions: 10.0.26100.8457
    Fixed in: 2026-07-14 update
  • Apple — macOS CoreWLAN
    Vulnerable versions: 26.3.1 (25D2128)
    Fixed in: macOS 27

Remediation for Cisco Talos disclosure

Patches

  • Microsoft MSRC: CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177
  • Foxit PDF Reader/Editor 2026.1.2 (CVE-2026-57256) and 2026.2.1 (CVE-2026-91799)
  • Adobe Photoshop update of 2026-07-28 (CVE-2026-48388)
  • macOS 27 (TALOS-2026-2376)

Immediate actions

  • Apply the July 14, 2026 Microsoft security updates (NETIO.sys, tcpip.sys, Cloud Files Mini Filter) and the September 8, 2026 update for CVE-2026-80093
  • Update Foxit PDF Reader/Editor to 2026.2.1 or later (14.0.8 / 13.2.7 for PDF Editor)
  • Update Adobe Photoshop to the build released 2026-07-28 or later

Workarounds

  • Disable JavaScript in Foxit Reader and open untrusted PDFs in a sandbox or Protected View until updated
  • Do not run Adobe installers from user-writable working directories on shared systems

Longer-term hardening

  • Restrict standard users from writing to %TEMP% paths used by elevated installers where feasible
  • Monitor for unusual Cloud Filter API use by non-sync-provider processes
  • Upgrade macOS to version 27

CVEs associated with Cisco Talos disclosure

CVE-2026-48388, CVE-2026-57256, CVE-2026-91799, CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177

Weaknesses (CWE) in Cisco Talos disclosure

CWE-427, CWE-416, CWE-843, CWE-823, CWE-125, CWE-912

Timeline of Cisco Talos disclosure

  • Talos contacts Apple about the macOS CoreWLAN information disclosure (TALOS-2026-2376)
  • Photoshop installer privilege escalation (CVE-2026-48388) reported to Adobe
  • Foxit Reader CBF_Widget use-after-free (CVE-2026-57256) reported to Foxit
  • Cloud Files Mini Filter use-after-free (CVE-2026-58613) and tcpip.sys out-of-bounds read (CVE-2026-49177) disclosed to Microsoft
  • NETIO.sys (CVE-2026-50475) and Cloud Files Mini Filter type confusion (CVE-2026-80093) reported to Microsoft
  • Foxit Reader Array use-after-free (CVE-2026-91799) disclosed to Foxit
  • Foxit releases fixes including CVE-2026-57256 (Reader/Editor 2026.1.2)
  • Microsoft patches CVE-2026-50475, CVE-2026-58613 and CVE-2026-49177
  • Adobe patches Photoshop installer CVE-2026-48388
  • Microsoft patches Cloud Files Mini Filter type confusion CVE-2026-80093
  • Apple addresses CoreWLAN disclosure in macOS 27 and TALOS-2026-2376 goes public
  • Foxit releases fix for CVE-2026-91799 (Reader/Editor 2026.2.1)
  • Cisco Talos publishes the vulnerability roundup covering all eight issues

Sources cited for Cisco Talos disclosure

Detection coverage for TL-2026-3011

As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3011 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
5 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats