Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Web Interface Vulnerabilities (CVE‑2026‑90443) in CISA Malcolm Threaten Critical Infrastructure

CISA’s Malcolm platform is affected by a reflected XSS (CVE‑2026‑90443) and several related code‑execution flaws that can be exploited without authentication. The issue highlights the importance of continuous control mapping and audit‑ready evidence for web‑application security in regulated sectors.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
cisa.gov

Critical Web Interface Vulnerabilities (CVE‑2026‑90443) in CISA Malcolm Threaten Critical Infrastructure

What It Is – CISA’s “Malcolm” monitoring platform contains a chain of web‑application flaws, the most severe being CVE‑2026‑90443 (reflected XSS) that can be triggered without authentication. The advisory lists additional issues such as OS‑command injection, path‑traversal, SSRF, authentication bypass, default credentials, and insecure third‑party components.

Exploitability – The XSS flaw is publicly disclosed and can be weaponised with a crafted URL; other listed weaknesses are also exploitable in the wild. The CVSS base score is 8.8 (high).

Affected Products – CISA Malcolm (all current releases).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous validation that web‑application controls (input sanitisation, authentication, least‑privilege) are enforced and evidentially logged.
  • A single un‑authenticated flaw can undermine the audit trail for critical‑infrastructure monitoring, eroding the trust signal demanded by regulators and enterprise partners.
  • Mapping these gaps to a unified control objective (secure application development & configuration) provides evidence that satisfies multiple frameworks (e.g., NIST CSF, ISO 27001) in one assessment.

Recommended Actions

  • Prioritise patching or mitigations for the XSS and related code‑execution flaws; verify that authentication is enforced on all UI endpoints.
  • Conduct a control‑mapping exercise against the “Secure Application Development” objective in the Verisq Common Framework, capturing remediation evidence for audit readiness.
  • Deploy a web‑application firewall (WAF) with rule sets that detect reflected XSS, SSRF, and command‑injection patterns while logging all blocked attempts.
  • Review third‑party component inventories and replace any with known vulnerabilities.

Source: CISA Advisory – ICSA‑26‑254‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →