Product
CISA Malcolm versions prior to v26.06.0 contain multiple critical vulnerabilities, including command injection, path traversal, and SSRF, allowing attackers to achieve remote code execution, authentication bypass, and unauthorized data access.