Affected users should update their CISA Malcolm instance to version 26.06.0 or later. The September 2026 release or subsequent versions contain the necessary fixes. No temporary workarounds are documented in the advisory.
Quick answers
What is CVE-2026-90444?
Affected users should update their CISA Malcolm instance to version 26.06.0 or later. The September 2026 release or subsequent versions contain the necessary fixes. No temporary workarounds are documented in the advisory.
How severe is CVE-2026-90444?
high
Is CVE-2026-90444 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-90444 be mitigated?
Affected users should update their CISA Malcolm instance to version 26.06.0 or later. The September 2026 release or subsequent versions contain the necessary fixes. No temporary workarounds are documented in the advisory.
CVSS
—
Vendor
CISA
Published
Oct 2, 2026 · 03:09
Patch
Unknown / not confirmed
Affected products
CISA Malcolm
Mitigation
Affected users should update their CISA Malcolm instance to version 26.06.0 or later. The September 2026 release or subsequent versions contain the necessary fixes. No temporary workarounds are documented in the advisory.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an industrial control systems advisory detailing six vulnerabilities in the CISA Malcolm platform. The flaws range from cross-site scripting and OS command injection to path traversal and SSRF. All listed vulnerabilities affect CISA Malcolm versions earlier than v26.06.0, with the latest release (September 2026 or later) resolving the issues. Affected installations are urged to update immediately.