HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Multiple High‑Severity Vulnerabilities in CISA Malcolm Network Traffic Analyzer Enable DoS and Arbitrary Code Execution

CISA disclosed six CVEs affecting Malcolm versions prior to 26.07.0, allowing denial‑of‑service or remote code execution through malicious archive uploads. For SOC 2‑ready organizations the flaws highlight gaps in input validation and resource‑throttling controls that must be mapped, monitored, and evidenced.

LiveThreat™ Intelligence · 📅 August 19, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Multiple High‑Severity Vulnerabilities in CISA Malcolm Network Traffic Analyzer (CVE‑2026‑63133, CVE‑2026‑63134, CVE‑2026‑63177, CVE‑2026‑55676, CVE‑2026‑19670, CVE‑2026‑19671) Enable DoS and Arbitrary Code Execution

What It Is – CISA Malcolm is a network‑traffic‑analysis suite used by many critical‑infrastructure operators. Six CVEs have been disclosed, covering unthrottled resource allocation, path‑traversal during archive extraction, and unsafe handling of highly compressed data. Successful exploitation can lead to denial‑of‑service (DoS) or remote code execution (RCE).

Exploitability – The vulnerabilities are publicly disclosed, patches exist, and proof‑of‑concept exploits for the archive‑extraction flaws have been demonstrated. CVSS scores range from 6.5 (Medium) to 8.8 (Critical).

Affected Products – CISA Malcolm versions < 26.06.1 (CVE‑2026‑55676) and < 26.07.0 (CVE‑2026‑63133, ‑63134, ‑63177) and ≤ 26.07.1 (CVE‑2026‑19670, ‑19671).

Why It Matters for Compliance & Audit Readiness

  • Control‑mapping gap – The flaws stem from missing input‑validation and resource‑throttling controls, which map to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
  • Evidence of due diligence – Demonstrating timely patching and remediation provides concrete audit evidence that your organization maintains a defensible security posture.
  • Continuous monitoring – Ongoing vulnerability‑scanning and automated remediation tracking are required to satisfy the “monitoring of controls” criteria in SOC 2.

Recommended Actions

  • Upgrade all Malcolm deployments to version 26.07.0 or later.
  • Verify that archive‑extraction processes enforce directory‑traversal protection and limit file‑system object creation.
  • Add the Malcolm version and patch status to your asset‑inventory and continuous vulnerability‑management pipeline.
  • Map the remediation to SOC 2 CC6.1/CC7.1 controls and capture screenshots or tool logs as audit evidence.

Source: CISA Advisory ICSA‑26‑230‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-01

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →