{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/malcolm--v26.06.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Malcolm (\u003c v26.06.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cisa","rce","ssrf"],"_cs_type":"advisory","_cs_vendors":["CISA"],"content_html":"\u003cp\u003eCISA Malcolm versions prior to v26.06.0 are affected by a suite of high-severity vulnerabilities discovered in its web-based interfaces and API endpoints. These vulnerabilities range from unauthenticated Cross-Site Scripting (CVE-2026-90443) to authenticated Remote Code Execution (CVE-2026-90444), Path Traversal (CVE-2026-90445), Server-Side Request Forgery (CVE-2026-90446), and Authentication Bypass via header manipulation (CVE-2026-90447). The flaws reside in how the application processes user-supplied input, manages file uploads, and handles internal routing.\u003c/p\u003e\n\u003cp\u003eThese vulnerabilities allow attackers, depending on their authentication status, to execute arbitrary operating system commands with application privileges, traverse directory structures to write files to arbitrary locations, and interact with internal data stores. Malcolm is deployed globally across sectors including Energy, IT, and Water, making the timely application of vendor-provided patches essential for maintaining operational integrity.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to full system compromise, unauthorized data exfiltration from internal backend services, and the injection of malicious records into diagnostic or logging data. Given the application's role in network traffic analysis and its deployment within critical infrastructure environments, successful exploitation could provide an attacker with a foothold for lateral movement into sensitive segments of an internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all instances of CISA Malcolm immediately.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all CISA Malcolm instances to the September 2026 release (v26.06.0 or later) as specified in the vendor remediation guidance.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering for web and API interfaces to ensure only authorized personnel can interact with the system.\u003c/li\u003e\n\u003cli\u003eReview all system logs for anomalous file upload activity or unexpected outbound connections from the Malcolm instance, which may indicate exploitation attempts related to CVE-2026-90444 or CVE-2026-90446.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T17:06:51Z","date_published":"2026-10-01T17:06:51Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cisa-malcolm/","summary":"CISA Malcolm versions prior to v26.06.0 contain multiple critical vulnerabilities, including command injection, path traversal, and SSRF, allowing attackers to achieve remote code execution, authentication bypass, and unauthorized data access.","title":"Multiple Vulnerabilities in CISA Malcolm","url":"https://feed.craftedsignal.io/briefs/2026-10-cisa-malcolm/"}],"language":"en","title":"CraftedSignal Threat Feed - Malcolm (\u003c V26.06.0)","version":"https://jsonfeed.org/version/1.1"}