Microsoft, Adobe, Apple, and Foxit security flaws
What happened
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. Adobe Photoshop privilege escalation (gaining powers on a system that the user was not given) vulnerability TALOS-2026-2360 (CVE-2026-48388 (the public catalogue number for a specific software flaw)) is a privilege escalation vulnerability in the Installation functionality of Photoshop (version(s): Photoshop_Set-Up.exe version 2.11.0.30). Apple is a software and consumer electronics company based in Cupertino. Microsoft is a software and software development company based in Redmond.
An attacker can replace files with a specially crafted malformed file to trigger this vulnerability and lead to privilege escalation. Apple macOS CoreWLAN information disclosure vulnerability TALOS-2026-2376 is an information disclosure vulnerability in the CoreWLAN functionality of macOS (version(s): 26.3.1(25D2128)).
An attacker can call a sequence of APIs to trigger this vulnerability. Foxit Reader code execution and use-after-free vulnerabilities TALOS-2026-2420 (CVE-2026-57256) is a code execution vulnerability in the Javascript checkbox CBF_Widget functionality of Foxit Reader (version(s): 2026.1.1.36485).
Sources & evidence
- Cisco Talos Primary / official
Microsoft, Adobe, Apple, and Foxit vulnerabilities ↗
https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerabilities/