CISA disclosed six vulnerabilities in the CISA Malcolm network traffic analysis tool suite. The most severe is CVE-2026-55676 (CVSS 8.8), which allows authenticated users with the upload-only role to upload and execute arbitrary PHP code. Two RBAC bypass vulnerabilities (CVE-2026-63177 and CVE-2026-19670) exploit discrepancies between Nginx routing and the Lua RBAC layer's URI normalization. Two denial-of-service vulnerabilities (CVE-2026-63133 and CVE-2026-19671) exploit resource exhaustion during archive extraction. Patches are available across versions 26.06.1, 26.07.0, and 26.08.0.
Decompression Bomb
1 post
CISA Malcolm (CVE-2026-55676, CVE-2026-63133, CVE-2026-63134 +3 more)