CriticalCISAAug 18, 2026

CISA Malcolm

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. The following versions of CISA Malcolm are affected: Malcolm <26.06.1 (CVE-2026-55676) Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671) CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplifica

Why it matters

The weakness can enable direct compromise with limited attacker prerequisites, making internet-facing assets the first place to look.

What defenders should do

Identify affected versions, prioritize internet-facing systems, and apply the vendor remediation.

Verify at the source

CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at www.cisa.gov →

Need to validate an indicator or network range?
Move from reading to action with the free CyberKit toolbox.
Use security tools