Cisco Talos’ vulnerability roundup is a useful reminder that risk is not limited to one category of product. The disclosures cover TP-Link Archer AX53 routers, Adobe Photoshop, OpenVPN, and Norton VPN, showing how vulnerabilities can appear across network infrastructure, desktop software, VPN clients, and remote-access tools. Talos disclosed eight TP-Link issues, one Photoshop issue, one OpenVPN issue, and one Norton VPN issue. Most were patched through vendor disclosure, while the Norton VPN issue was reportedly discovered in use before a patch was available.
The TP-Link issues are especially important because routers often sit at the edge of home, branch, and small-business networks. The reported flaws include stack-based buffer overflow, command injection, and arbitrary file-read risks in TP-Link Archer AX53 functionality, including OpenVPN and dnsmasq configuration restore paths. If exploited, these weaknesses could allow arbitrary code execution or sensitive file access. That is not “just a home router problem”; it is the edge device politely becoming the attacker’s foothold, because apparently the perimeter enjoys betrayal.
The OpenVPN vulnerability, CVE-2026-35058, is also worth attention because VPN infrastructure is often considered trusted by default. Talos describes it as a reachable assertion issue in TLS Crypt v2 Client Key Extraction that can be triggered through crafted network packets, leading to denial of service. For organizations relying on VPN availability, even DoS conditions can create real operational disruption.
The Photoshop and Norton VPN issues show a different but equally important pattern: local privilege escalation through installation processes. In both cases, a low-privilege user could manipulate installation behavior, potentially leading to elevated privileges or arbitrary file deletion. This reinforces the need to secure software deployment paths, installer permissions, endpoint hardening, and application update workflows.
Organizations should update affected products, review exposed TP-Link router management access, restrict VPN and router admin interfaces, monitor for suspicious configuration changes, and ensure desktop software installers are not writable or replaceable by low-privilege users. The broader lesson is simple: vulnerability management must cover routers, VPNs, endpoints, creative tools, and installers. Attackers do not care whether the weak point is a firewall-facing router or a photo-editing installer. They only care that it works.

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed eight vulnerabilities in TP-Link, and one each in Adobe Photoshop, OpenVPN, and Gen Digital's Norton VPN. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability
Source: TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities via Cisco Talos — published 19 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.