Multiple High‑Severity Vulnerabilities in CISA Malcolm Network Traffic Analyzer (CVE‑2026‑63133, CVE‑2026‑63134, CVE‑2026‑63177, CVE‑2026‑55676, CVE‑2026‑19670, CVE‑2026‑19671) Enable DoS and Arbitrary Code Execution
What It Is – CISA Malcolm is a network‑traffic‑analysis suite used by many critical‑infrastructure operators. Six CVEs have been disclosed, covering unthrottled resource allocation, path‑traversal during archive extraction, and unsafe handling of highly compressed data. Successful exploitation can lead to denial‑of‑service (DoS) or remote code execution (RCE).
Exploitability – The vulnerabilities are publicly disclosed, patches exist, and proof‑of‑concept exploits for the archive‑extraction flaws have been demonstrated. CVSS scores range from 6.5 (Medium) to 8.8 (Critical).
Affected Products – CISA Malcolm versions < 26.06.1 (CVE‑2026‑55676) and < 26.07.0 (CVE‑2026‑63133, ‑63134, ‑63177) and ≤ 26.07.1 (CVE‑2026‑19670, ‑19671).
Why It Matters for Compliance & Audit Readiness
- Control‑mapping gap – The flaws stem from missing input‑validation and resource‑throttling controls, which map to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
- Evidence of due diligence – Demonstrating timely patching and remediation provides concrete audit evidence that your organization maintains a defensible security posture.
- Continuous monitoring – Ongoing vulnerability‑scanning and automated remediation tracking are required to satisfy the “monitoring of controls” criteria in SOC 2.
Recommended Actions
- Upgrade all Malcolm deployments to version 26.07.0 or later.
- Verify that archive‑extraction processes enforce directory‑traversal protection and limit file‑system object creation.
- Add the Malcolm version and patch status to your asset‑inventory and continuous vulnerability‑management pipeline.
- Map the remediation to SOC 2 CC6.1/CC7.1 controls and capture screenshots or tool logs as audit evidence.
Source: CISA Advisory ICSA‑26‑230‑01