<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Malcolm (&lt; V26.06.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/malcolm--v26.06.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 17:06:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/malcolm--v26.06.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in CISA Malcolm</title><link>https://feed.craftedsignal.io/briefs/2026-10-cisa-malcolm/</link><pubDate>Thu, 01 Oct 2026 17:06:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cisa-malcolm/</guid><description>CISA Malcolm versions prior to v26.06.0 contain multiple critical vulnerabilities, including command injection, path traversal, and SSRF, allowing attackers to achieve remote code execution, authentication bypass, and unauthorized data access.</description><content:encoded><![CDATA[<p>CISA Malcolm versions prior to v26.06.0 are affected by a suite of high-severity vulnerabilities discovered in its web-based interfaces and API endpoints. These vulnerabilities range from unauthenticated Cross-Site Scripting (CVE-2026-90443) to authenticated Remote Code Execution (CVE-2026-90444), Path Traversal (CVE-2026-90445), Server-Side Request Forgery (CVE-2026-90446), and Authentication Bypass via header manipulation (CVE-2026-90447). The flaws reside in how the application processes user-supplied input, manages file uploads, and handles internal routing.</p>
<p>These vulnerabilities allow attackers, depending on their authentication status, to execute arbitrary operating system commands with application privileges, traverse directory structures to write files to arbitrary locations, and interact with internal data stores. Malcolm is deployed globally across sectors including Energy, IT, and Water, making the timely application of vendor-provided patches essential for maintaining operational integrity.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can lead to full system compromise, unauthorized data exfiltration from internal backend services, and the injection of malicious records into diagnostic or logging data. Given the application's role in network traffic analysis and its deployment within critical infrastructure environments, successful exploitation could provide an attacker with a foothold for lateral movement into sensitive segments of an internal network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all instances of CISA Malcolm immediately.</p>
<ul>
<li>Upgrade all CISA Malcolm instances to the September 2026 release (v26.06.0 or later) as specified in the vendor remediation guidance.</li>
<li>Implement strict ingress filtering for web and API interfaces to ensure only authorized personnel can interact with the system.</li>
<li>Review all system logs for anomalous file upload activity or unexpected outbound connections from the Malcolm instance, which may indicate exploitation attempts related to CVE-2026-90444 or CVE-2026-90446.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cisa</category><category>rce</category><category>ssrf</category></item></channel></rss>