CISA Malcolm Update Addresses Fifteen Security Vulnerabilities
Quick Answer
The authority published ICSA-26-254-01 for CISA Malcolm before v26.06.0. CISA documents fifteen web, command, path, authorization, authentication, credential, certificate, redirect, dependency, and password-hashing weaknesses in Malcolm. The authority directs affected users to the September 2026 release or later and calls out an additional certificate-validation setting. Affected deployments should be matched to the authority's exact scope and moved to the supported fixed release.
Confirm Scope And Apply The Supported Fix
What to do now: Inventory CISA Malcolm before v26.06.0, match the exact affected release or feature, apply the authority-supported fixed build or service remediation, validate the dependent workflow, and preserve evidence.
Last verified: 2026-10-02 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | CISA Malcolm before v26.06.0 |
|---|---|
| Advisory | ICSA-26-254-01 |
| CVEs | CVE-2026-90443, CVE-2026-90444, CVE-2026-90445, CVE-2026-90446, CVE-2026-90447, CVE-2026-90448, CVE-2026-90449, CVE-2026-90450, CVE-2026-90451, CVE-2026-90452, CVE-2026-90453, CVE-2026-90454, CVE-2026-90455, CVE-2026-90456, CVE-2026-90457 |
| Authoritative release date | 2026-10-01 (CISA public advisory date; CSAF current release 2026-10-01 06:00 UTC) |
| Authority revision date | Initial public publication; no later material revision stated when verified |
| Affected versions | CISA Malcolm releases before v26.06.0. |
| Fixed version | CISA Malcolm September 2026 release or later, with KEYCLOAK_SSL_VERIFY explicitly enabled where certificate validation is required |
| CVSS base score | 3.5–8.8 (official CVSS v3.1 range) |
| CVSS severity | Low to High |
| Exploitation status | CISA reports no known public exploitation specifically targeting these vulnerabilities; no exploitation claim is inferred. |
What Changed
CISA documents fifteen web, command, path, authorization, authentication, credential, certificate, redirect, dependency, and password-hashing weaknesses in Malcolm. The authority directs affected users to the September 2026 release or later and calls out an additional certificate-validation setting.
What To Validate Now
- Inventory. Locate CISA Malcolm before v26.06.0 deployments, versions, enabled features, exposure paths, owners, and dependent services.
- Establish applicability. Match the exact product and affected-version statement in ICSA-26-254-01. Do not generalize the finding to another product, service, or release.
- Remediate. Follow the authority-supported disposition: CISA Malcolm September 2026 release or later, with KEYCLOAK_SSL_VERIFY explicitly enabled where certificate validation is required.
- Validate. Confirm the corrected release or mitigation state, restrict unnecessary exposure, validate safety and operational workflows, review relevant authentication, network, application, and device telemetry, and document exceptions.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Test changes in a representative environment, preserve configurations and forensic evidence before destructive action, coordinate with operations and safety owners, and treat exposure reduction as a mitigation rather than proof of remediation.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

