An advisory published on October 1, 2026 lists flaws in CISA Malcolm, including XSS, command injection and path traversal. Version September 2026 or later fixes the issues.
The CISA advisory describes vulnerabilities in Malcolm, a product used in sectors including energy, information technology, and water and wastewater. The listed flaws include XSS, operating-system command injection, path traversal, SSRF, and authentication and authorization issues. The alert reports an overall CVSS 3 score of 8.8. CVE-2026-90443 concerns a web interface that can execute a script in the application context when a user visits a link crafted by an attacker; its scores are 5.4 under CVSS 3.1 and 5.3 under CVSS 4.0. CVE-2026-90444 describes command execution through manipulated filenames submitted by an authenticated user.
CISA says the latest Malcolm version, September 2026 or later, fixes the vulnerabilities and recommends updating affected instances. Consult the original advisory and its CSAF summary to confirm scope, versions, and guidance before acting; also verify the installed version and manufacturer notices. If using AI to study the advisory, do not submit credentials, log data, or identifiable internal information.