Executive Summary
Facts Only
* Affected product is CISA Malcolm.
* Vulnerabilities include Improper Neutralization of Input During Web Page Generation (Cross-site Scripting), OS Command Injection, Path Traversal, Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, and Dependency on Vulnerable Third-Party Component.
* Affected sectors include Energy, Information Technology, Water and Wastewater.
* CVE-2026-90443 involves reflecting request URL into a script context and allowing unauthenticated execution.
* CVE-2026-90444 allows authenticated attackers to execute operating system commands via file-transfer interfaces.
* CVE-2026-90445 allows authenticated attackers to write arbitrary files by traversing directory paths during file uploads.
* CVE-2026-90446 allows authenticated attackers to use application credentials against internal endpoints via path interpolation (SSRF).
* CVE-2026-90453 allows redirection based on the Referer header during file uploads.
* CVE-2026-90457 details a weakness in password hashing that permits offline recovery of passwords.
* Remediation requires updating to Malcolm version September 2026 or later.
Full Take
From the original · CISA ICS Advisories
Summary The following versions of CISA Malcolm are affected: - Malcolm | CVSS | Vendor | Equipment | Vulnerabilities | |---|---|---|---| | v3 8.8 | CISA | CISA Malcolm | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted…Read the full story at cisa.gov
Sentinel — Human
This text is a highly structured, fact-based enumeration of cybersecurity vulnerabilities for a specific software product. Its precision suggests it originates from an authoritative source, likely CISA, rather than general synthetic content.
