Critical Web Interface Vulnerabilities (CVE‑2026‑90443) in CISA Malcolm Threaten Critical Infrastructure
What It Is – CISA’s “Malcolm” monitoring platform contains a chain of web‑application flaws, the most severe being CVE‑2026‑90443 (reflected XSS) that can be triggered without authentication. The advisory lists additional issues such as OS‑command injection, path‑traversal, SSRF, authentication bypass, default credentials, and insecure third‑party components.
Exploitability – The XSS flaw is publicly disclosed and can be weaponised with a crafted URL; other listed weaknesses are also exploitable in the wild. The CVSS base score is 8.8 (high).
Affected Products – CISA Malcolm (all current releases).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous validation that web‑application controls (input sanitisation, authentication, least‑privilege) are enforced and evidentially logged.
- A single un‑authenticated flaw can undermine the audit trail for critical‑infrastructure monitoring, eroding the trust signal demanded by regulators and enterprise partners.
- Mapping these gaps to a unified control objective (secure application development & configuration) provides evidence that satisfies multiple frameworks (e.g., NIST CSF, ISO 27001) in one assessment.
Recommended Actions
- Prioritise patching or mitigations for the XSS and related code‑execution flaws; verify that authentication is enforced on all UI endpoints.
- Conduct a control‑mapping exercise against the “Secure Application Development” objective in the Verisq Common Framework, capturing remediation evidence for audit readiness.
- Deploy a web‑application firewall (WAF) with rule sets that detect reflected XSS, SSRF, and command‑injection patterns while logging all blocked attempts.
- Review third‑party component inventories and replace any with known vulnerabilities.
Source: CISA Advisory – ICSA‑26‑254‑01