CISA Malcolm

Plan PatchCVSS 8.8ICS-CERT ICSA-26-230-01Aug 18, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities in Malcolm (CWE-770 resource exhaustion, CWE-22 path traversal, CWE-434 unrestricted file upload, CWE-863 improper authorization, CWE-409 uncontrolled resource consumption) could allow an authenticated attacker to execute arbitrary code or cause denial-of-service conditions on the system.

What this means
What could happen
An attacker with valid credentials could execute arbitrary code on the Malcolm system or cause it to become unavailable, potentially disrupting network traffic analysis and security monitoring operations.
Who's at risk
Network security teams, SOC analysts, and IT staff operating Malcolm network traffic analysis and monitoring systems. Any organization using Malcolm for packet capture, network intelligence analysis, or security event correlation should prioritize this update.
How it could be exploited
An attacker with legitimate access to Malcolm could exploit input validation, file handling, or permission flaws to upload malicious files or bypass security checks, resulting in code execution or resource exhaustion. The attack requires network access to Malcolm and valid user credentials.
Prerequisites
  • Network access to Malcolm instance
  • Valid Malcolm user credentials
  • Application running an affected version
remotely exploitablerequires valid credentialsaffects security monitoring systemslow complexity exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (3)
3 with fix
ProductAffected VersionsFix Status
Malcolm<26.07.026.07.0
Malcolm<26.06.126.06.1
Malcolm≤ 26.07.126.08.0
Remediation & Mitigation
0/4
Do now
0/1
Malcolm
WORKAROUNDRestrict Malcolm access to authorized users only via network firewall or VPN
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Malcolm
HOTFIXUpdate Malcolm to version 26.07.0 or later
HOTFIXUpdate Malcolm to version 26.08.0 if running version 26.07.1 or earlier
Long-term hardening
0/1
Malcolm
HARDENINGEnforce strong password policies and multi-factor authentication for Malcolm user accounts
API: /api/v1/advisories/b2677a14-4796-4db6-8f27-f3bc2bbc3e42

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

CISA Malcolm | CVSS 8.8 - OTPulse