MalwareTips News Security updates fix flaws in Windows, Photoshop, macOS and Foxit Reader

Which affected product will you check for updates first?

  • Windows

    Votes: 2 100.0%
  • Foxit Reader

    Votes: 0 0.0%
  • Photoshop

    Votes: 0 0.0%
  • macOS

    Votes: 0 0.0%
  • I do not use these

    Votes: 0 0.0%

  • Total voters
    2

News Now

Happening Now
Verified
MalwareTips-news-180.jpg

Image: Cisco Talos

Microsoft, Adobe, Apple and Foxit have patched recently disclosed security flaws affecting Windows, Photoshop, macOS and Foxit Reader. People using these products should install available updates, especially because malicious PDFs or files could exploit some of the bugs.


What users should do​

The vendors have released fixes for all vulnerabilities covered in the Cisco Talos roundup. Check Windows Update and the built-in update tools for Photoshop, macOS and Foxit Reader rather than relying only on automatic updates having already run.

  • Update Foxit Reader before opening PDFs from unfamiliar or unexpected sources.
  • Install current Windows updates to address flaws that could expose information, crash the system or help an attacker gain higher privileges.
  • Update Photoshop if you used Photoshop_Set-Up.exe version 2.11.0.30.
  • Install the latest available macOS update if your Mac is running macOS 26.3.1 build 25D2128.

Malicious PDFs pose the clearest everyday risk​

Foxit Reader 2026.1.1.36485 contains CVE-2026-57256, which can allow remote code execution through a specially crafted file. Remote code execution means an attacker may be able to run commands or software on the affected computer.

A second Foxit flaw, CVE-2026-91799, involves JavaScript embedded in a malicious PDF. It can corrupt memory and potentially allow arbitrary code execution.

Windows flaws affect drivers and cloud files​

Two Windows Cloud Files Mini Filter Driver flaws affect listed builds in the Windows 10.0.26100 line. One, CVE-2026-58613, could let a dedicated malicious application elevate its privileges, meaning it gains more control than it should have.

Separate bugs in the NETIO.sys and tcpip.sys network drivers could disclose sensitive information. The tcpip.sys issue, CVE-2026-49177, could also cause a denial of service, making the affected system or service unavailable.

Photoshop and macOS issues​

CVE-2026-48388 affects the installation function in Photoshop_Set-Up.exe version 2.11.0.30. Replacing files with a specially crafted malformed file could lead to privilege escalation.

Talos also reported an information-disclosure flaw in the CoreWLAN component of macOS 26.3.1 build 25D2128. The issue can be triggered through a sequence of application programming interface calls.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top