CISA Warns of Multiple Vulnerabilities in Malcolm Network Traffic Analysis Tool
Advisory ICSA-26-230-01 details flaws allowing arbitrary code execution and denial-of-service; patches available for most issues.
Key Takeaways
- CISA Malcolm has multiple vulnerabilities, including arbitrary code execution and denial-of-service.
- CVE-2026-55676 allows authenticated users with upload-only role to execute arbitrary PHP code.
- CVE-2026-63133 and CVE-2026-63134 involve malicious archive handling leading to resource exhaustion and path traversal.
- Patches are available for most issues: upgrade to Malcolm 26.06.1 or 26.07.0 as applicable.
- Details for CVE-2026-63177, CVE-2026-19670, and CVE-2026-19671 are not fully disclosed in the advisory.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



_Dzmitry_Skazau_Alamy.jpg?width=720&quality=80&disable=upscale)