Cyber Resilience
← All news
Confirmed

CISA Malcolm

Our takeCISA Malcolm advisory ICSA-26-230-01 lists five CVEs with confirmed exploitation that can lead to arbitrary code execution or DoS. Update to 26.07.2 or later if you run Malcolm.
Sources (2)
What this means for you — Security leader:Update any Malcolm deployments to 26.07.2 or later. The CISA advisory confirms active exploitation of these CVEs leading to arbitrary code execution or DoS.
What this means for you — Lean IT orgs:If your organization runs Malcolm for network monitoring, update it immediately to version 26.07.2 or newer. Most lean teams can do this through the built-in update function or by redeploying the container.
What this means for you — MSP:Check all client environments running Malcolm and upgrade to 26.07.2+. CISA confirms active exploitation; patch this before adversaries scan for unpatched instances.
What this means for you — Researcher:Review the CISA advisory and linked CSAF for Malcolm. Five CVEs with confirmed exploitation; focus on the arbitrary code execution paths in versions before 26.07.2.