Upgrade Malcolm to version 26.06.1 or later to address CVE-2026-55676. Upgrade to version 26.07.0 or later to address CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177. For CVE-2026-19670 and CVE-2026-19671, monitor CISA advisory for updates. Restrict access to the upload functionality to trusted users only.
Quick answers
What is CVE-2026-63133?
Upgrade Malcolm to version 26.06.1 or later to address CVE-2026-55676. Upgrade to version 26.07.0 or later to address CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177. For CVE-2026-19670 and CVE-2026-19671, monitor CISA advisory for updates. Restrict access to the upload functionality to trusted users only.
How severe is CVE-2026-63133?
high, CVSS 8.8
Is CVE-2026-63133 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-63133 be mitigated?
Upgrade Malcolm to version 26.06.1 or later to address CVE-2026-55676. Upgrade to version 26.07.0 or later to address CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177. For CVE-2026-19670 and CVE-2026-19671, monitor CISA advisory for updates. Restrict access to the upload functionality to trusted users only.
CVSS
8.8
Vendor
CISA
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
CISA Malcolm
Mitigation
Upgrade Malcolm to version 26.06.1 or later to address CVE-2026-55676. Upgrade to version 26.07.0 or later to address CVE-2026-63133, CVE-2026-63134, and CVE-2026-63177. For CVE-2026-19670 and CVE-2026-19671, monitor CISA advisory for updates. Restrict access to the upload functionality to trusted users only.
CISA has released an advisory covering multiple vulnerabilities in its Malcolm network traffic analysis tool suite. The most severe flaw, CVE-2026-55676, allows an authenticated user with the upload-only role to execute arbitrary PHP code as www-data. Other issues include resource exhaustion via malicious archives (CVE-2026-63133), path traversal (CVE-2026-63134), and additional vulnerabilities affecting versions up to 26.07.1. Patches are available for most issues, but details for some CVEs remain incomplete.