Our takeCISA Malcolm advisory ICSA-26-230-01 lists five CVEs with confirmed exploitation that can lead to arbitrary code execution or DoS. Update to 26.07.2 or later if you run Malcolm.Cyber Resilience desk
Sources (2)
- cisa_advisories · cisa_advisories
- cisa_ics · cisa_ics
What this means for you — Security leader:Update any Malcolm deployments to 26.07.2 or later. The CISA advisory confirms active exploitation of these CVEs leading to arbitrary code execution or DoS.
What this means for you — Lean IT orgs:If your organization runs Malcolm for network monitoring, update it immediately to version 26.07.2 or newer. Most lean teams can do this through the built-in update function or by redeploying the container.
What this means for you — MSP:Check all client environments running Malcolm and upgrade to 26.07.2+. CISA confirms active exploitation; patch this before adversaries scan for unpatched instances.
What this means for you — Researcher:Review the CISA advisory and linked CSAF for Malcolm. Five CVEs with confirmed exploitation; focus on the arbitrary code execution paths in versions before 26.07.2.