← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 12:00via CISA Alerts

CISA Malcolm

Brief

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. The following versions of CISA Malcolm are affected: Malcolm 26.

  • 1 (CVE-2026-55676) Malcolm 26.
  • 0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Malcolm =26.
  • 1 (CVE-2026-19670, CVE-2026-19671) CVSS Vendor Equipment Vulnerabilities

v3 8.8 CISA CISA Malcolm Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplification)

Background

Critical Infrastructure Sectors: Information Technology

Countries/Areas Deployed: Worldwide

Company Headquarters Location: United States

Read more on CISA Alerts