Back to advisories

CISA Malcolm

CISA Malcolm, widely deployed in energy and IT critical infrastructure, contains multiple critical vulnerabilities including OS command injection, authentication bypass, and path traversal. Attackers exploiting these flaws can execute arbitrary commands, bypass access controls, and read or modify sensitive data. Patch availability exists in September 2026 versions and later.

CRITICALAdvisoryOct 02, 2026
Action required
Immediately inventory all Malcolm deployments in your environment. Prioritize upgrading to September 2026 version or later. If immediate patching is impossible, isolate affected systems from production networks and implement network segmentation around Malcolm instances.
Affected products
CISA MalcolmCISA
Linked articles