# Cisco Talos disclosure: Microsoft, Adobe, Apple, and Foxit vulnerabilities (CVE-2026-48388, CVE-2026-57256, CVE-2026-91799, CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177)

> Cisco Talos published a roundup of eight patched vulnerabilities it discovered: an Adobe Photoshop installer privilege escalation, an Apple macOS CoreWLAN location-history information disclosure (no CVE), two Foxit Reader JavaScript use-after-free code-execution flaws, and four Windows kernel-driver flaws (NETIO.sys, tcpip.sys, and two in the Cloud Files Mini Filter). None is reported as exploited in the wild.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3011
- **ID:** TL-2026-3011
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 5 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-48388, CVE-2026-57256, CVE-2026-91799, CVE-2026-50475, CVE-2026-58613, CVE-2026-80093, CVE-2026-49177

## Description

Cisco Talos (Kri Dontje) published a vulnerability roundup on 2026-10-07 covering eight issues found by Talos researchers (KPC, Marcin 'Icewall' Noga, Francesco Benvenuto). All have vendor fixes available.

Adobe Photoshop (CVE-2026-48388, TALOS-2026-2360, CVSS 8.2, CWE-427): the elevated installer Photoshop_Set-Up.exe 2.11.0.30 looks for 'Adobe Installer.exe' in the user-writable %TEMP%\winget\ directory before the legitimate program directory. A standard user who plants a file there gets code execution at high integrity, potentially SYSTEM. Fixed by Adobe on 2026-07-28.

Foxit Reader 2026.1.1.36485 has two JavaScript use-after-free flaws (both CVSS 7.8, CWE-416). CVE-2026-57256 (TALOS-2026-2420) is in the checkbox CBF_Widget functionality: the PoC calls resetForm() and deletePages() to free form-field array objects that are then accessed. CVE-2026-91799 (TALOS-2026-2446) is a use-after-free in Array object handling reachable through the resetForm method. Both need the victim to open a crafted PDF. Fixed in Foxit PDF Reader/Editor 2026.1.2 (July 2026) and 2026.2.1 (September 2026).

Windows Cloud Files Mini Filter Driver (build 10.0.26100.8457 and 10.0.26100.8655): CVE-2026-58613 (TALOS-2026-2426, CVSS 8.8, CWE-416) is a use-after-free in CldiStreamCompleteRequest. A sync provider that terminates without disconnecting leaves orphaned requests on a global countdown timer list, and the timer cleanup frees a request that is still referenced. CVE-2026-80093 (TALOS-2026-2445, CVSS 8.8, CWE-843) is a type confusion in CldiStreamPrepareRequestForMoreProcessing. A race between CldStreamAbortOperation and a stack-based LIST_ENTRY sentinel makes the abort walker treat the sentinel as a request object, giving writes through a fake request pointer into another thread's kernel stack. Exploitation needs a registered sync provider, dehydrated placeholders, fetch-data callbacks, and the undocumented CfAbortOperation API timed against CfDisconnectSyncRoot. Both are local privilege escalations.

Two Windows information-disclosure bugs are reached through IRPs to IOCTL 0x120007. CVE-2026-50475 (TALOS-2026-2443, CVSS 5.5, CWE-823) is an off-by-one in NETIO.sys NsipGetAllInformationProviderParameters (the TableIndex check uses <= instead of <), which leaks 16 bytes of kernel data including tcpip.sys function pointers and so defeats ASLR. CVE-2026-49177 (TALOS-2026-2427, CVSS 8.4, CWE-125) is an out-of-bounds read in tcpip.sys IppQualifyAddresses when MaxDestCount exceeds 0x1f4, with a 0x1c-byte stride per iteration; it can cause information disclosure or denial of service. Microsoft patched both on 2026-07-14.

Apple macOS 26.3.1 (25D2128) CoreWLAN (TALOS-2026-2376, no CVE, CVSS 3.3, CWE-912): a low-privilege local process can read undocumented CWNetworkProfile properties (lastConnected, bssidList with latitude, longitude, accuracy and timestamps) and rebuild the device's location history without special permissions. Apple addressed it as defense-in-depth in macOS 27 (disclosed 2026-09-14).

The Talos page does not state in-the-wild exploitation. Search results indicate CVE-2026-58613 is not listed in CISA KEV, and no public exploitation was found for the others. These are patch-prioritization items; the kernel privilege-escalation and information-disclosure bugs are the sort that can be chained after initial access.

## MITRE ATT&CK

- T1574.008 Hijack Execution Flow: Path Interception by Search Order Hijacking
- T1203 Exploitation for Client Execution
- T1204.002 User Execution: Malicious File
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1005 Data from Local System

## Sources

- [Microsoft, Adobe, Apple, and Foxit vulnerabilities (Cisco Talos)](https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerabilities/)
- [TALOS-2026-2360 Adobe Photoshop installer privilege escalation](https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2360)
- [TALOS-2026-2376 Apple macOS CoreWLAN information disclosure](https://talosintelligence.com/vulnerability_reports/TALOS-2026-2376)
- [TALOS-2026-2420 Foxit Reader CBF_Widget use-after-free](https://talosintelligence.com/vulnerability_reports/TALOS-2026-2420)
- [TALOS-2026-2446 Foxit Reader Array use-after-free](https://talosintelligence.com/vulnerability_reports/TALOS-2026-2446)
- [TALOS-2026-2443 Windows NETIO.sys information disclosure](https://talosintelligence.com/vulnerability_reports/TALOS-2026-2443)
- [TALOS-2026-2426 Windows Cloud Files Mini Filter use-after-free](https://talosintelligence.com/vulnerability_reports/TALOS-2026-2426)
- [TALOS-2026-2445 Windows Cloud Files Mini Filter type confusion](https://talosintelligence.com/vulnerability_reports/TALOS-2026-2445)
- [TALOS-2026-2427 Windows tcpip.sys out-of-bounds read](https://talosintelligence.com/vulnerability_reports/TALOS-2026-2427)
- [Foxit Security Bulletins](https://www.foxit.com/support/security-bulletins.html)
- [MSRC CVE-2026-58613](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58613)
- [MSRC CVE-2026-80093](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80093)
- [MSRC CVE-2026-50475](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50475)
- [NVD CVE-2026-58613](https://nvd.nist.gov/vuln/detail/CVE-2026-58613)
- [macOS 27 Release Notes](https://developer.apple.com/documentation/macos-release-notes/macos-27-release-notes)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3011
