CISA Malcolm
Summary
CISA has released an alert detailing multiple vulnerabilities in CISA Malcolm, affecting versions prior to v26.06.0. These vulnerabilities include Cross-site Scripting, OS Command Injection, Path Traversal, and Server-Side Request Forgery, among others. The alert also provides a remediation by urging users to update to the latest version of Malcolm, available in September 2026 or later.
IFF Assessment
This article details multiple critical vulnerabilities in CISA Malcolm, posing a significant risk to defenders.
Severity
The CVSS score of 8.8 indicates a critical severity, reflecting the wide range of severe vulnerabilities including command injection, authentication bypass, and path traversal, which allow for significant impact on affected systems.
Defender Context
This alert highlights the importance of promptly patching systems running CISA Malcolm, as the identified vulnerabilities could be exploited by unauthenticated attackers. Defenders should prioritize updating to the latest version to mitigate risks such as arbitrary script execution and unauthorized access.