CISA Malcolm
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. The following versions of CISA Malcolm are affected: Malcolm <26.06.1 (CVE-2026-55676) Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671) CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplifica
Why it matters
The weakness can enable direct compromise with limited attacker prerequisites, making internet-facing assets the first place to look.
What defenders should do
Identify affected versions, prioritize internet-facing systems, and apply the vendor remediation.
Verify at the source
CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at www.cisa.gov →
Move from reading to action with the free CyberKit toolbox.