Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Multiple Zero-Day Vulnerabilities Disclosed in Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows Drivers

Cisco Talos disclosed seven new CVEs affecting Adobe, Apple, Foxit, and Microsoft products; patches are available. The findings underscore the need for continuous vulnerability management and auditable patch‑deployment evidence.

LiveThreat™ Intelligence · 📅 October 08, 2026· 📰 blog.talosintelligence.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
1 recommended
📰
Source
blog.talosintelligence.com

Multiple Zero‑Day Vulnerabilities Disclosed in Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows Drivers

What Happened – Cisco Talos’ research team reported seven new CVEs affecting Adobe Photoshop (CVE‑2026‑48388), Apple macOS CoreWLAN (TALOS‑2026‑2376), Foxit Reader (CVE‑2026‑57256, CVE‑2026‑91799), and Microsoft Windows drivers (CVE‑2026‑50475, CVE‑2026‑58613, CVE‑2026‑80093, CVE‑2026‑49177). All vendors have issued patches in line with their disclosure policies.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuous vulnerability‑management program that can detect, assess, and remediate newly disclosed flaws before they are weaponised.
  • Provides a concrete audit‑ready evidence point: timely patch deployment is a core control objective that satisfies multiple framework requirements (e.g., NIST CSF Identify, ISO 27001 A.12.6).
  • Highlights the importance of control mapping and automated evidence collection so organisations can prove they maintain an up‑to‑date software inventory and remediation workflow.

Who Is Affected – Enterprises across all sectors that run Adobe Photoshop, macOS, Foxit Reader, or Windows 10/11 environments – notably technology, finance, professional services, and education.

Recommended Actions

  • Verify the presence of the listed vulnerable versions in your asset inventory.
  • Deploy the vendor‑provided patches immediately and confirm successful installation.
  • Update your vulnerability‑management playbook to include these CVEs and capture patch‑deployment evidence for audit purposes.
  • Integrate continuous control‑mapping tools to maintain a real‑time view of remediation status.

Technical Notes –

  • Adobe Photoshop: Privilege escalation via malformed installer file (CVE‑2026‑48388).
  • Apple macOS: Information disclosure in CoreWLAN APIs (TALOS‑2026‑2376).
  • Foxit Reader: Remote code execution (CVE‑2026‑57256) and use‑after‑free leading to arbitrary code execution (CVE‑2026‑91799).
  • Microsoft Windows: Out‑of‑bounds, use‑after‑free, and type‑confusion bugs in NETIO.sys, Cloud Files Mini Filter, and tcpip.sys drivers (CVE‑2026‑50475, CVE‑2026‑58613, CVE‑2026‑80093, CVE‑2026‑49177).

Source: Cisco Talos Vulnerability Roundup

📰 Original Source
https://blog.talosintelligence.com/microsoft-adobe-apple-and-foxit-vulnerabilities/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →