CISA Advises Critical Vulnerabilities in Malcolm ICS Platform
Multiple high-severity flaws including XSS, OS command injection, and path traversal affect CISA Malcolm versions prior to v26.06.0
Key Takeaways
- CISA advisory ICSA-26-254-01 discloses six vulnerabilities in the CISA Malcolm platform.
- Affected versions are those prior to v26.06.0; the September 2026 or later release contains fixes.
- Vulnerabilities include XSS, OS command injection, path traversal, and SSRF, among others.
- The platform is used in critical infrastructure sectors such as Energy, IT, and Water and Wastewater worldwide.
- Users are strongly encouraged to update to the latest software version to resolve the flaws.
Quick answers
Related Security News
CISA Advises of Sensitive Information Exposure in Johnson Controls EasyIO Neo Series Controllers
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding CVE-2026-64892, a vulnerability in Johnson Controls EasyIO Neo Series EC and CW Controllers that could allow an attacker to gain access to sensitive information. The flaw stems from improper access controls in building automation controllers and impacts four specific firmware versions. Johnson Controls has released fixed firmware versions V3.3b64 (EC) and V3.3b26 (CW) to address the issue.
