As cited
Copy frozen at (site build).
vulnerabilities
CISA Malcolm
CISA published advisories for six vulnerabilities affecting Malcolm, a network traffic analysis tool used by critical infrastructure sectors worldwide. The flaws range from denial-of-service conditions caused by unbounded resource allocation to arbitrary code execution via unrestricted file uploads and authorization bypasses. Affected versions prior to 26.06.1, 26.07.0, and 26.08.0 require patching.
Why it matters: Organizations deploying Malcolm for network monitoring must update immediately: authenticated users can execute arbitrary code, bypass access controls, or crash the service, impacting visibility across monitored infrastructure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CISA Malcolm
CISA published advisories for six vulnerabilities affecting Malcolm, a network traffic analysis tool used by critical infrastructure sectors worldwide. The flaws range from denial-of-service conditions caused by unbounded resource allocation to arbitrary code execution via unrestricted file uploads and authorization bypasses. Affected versions prior to 26.06.1, 26.07.0, and 26.08.0 require patching.
Why it matters: Organizations deploying Malcolm for network monitoring must update immediately: authenticated users can execute arbitrary code, bypass access controls, or crash the service, impacting visibility across monitored infrastructure.
- Source published
- First seen by Cybersecurity Tracker