[Control Systems] CISA ICS security advisory (AV26-841)
Serial Number: AV26-841 Date: August 21, 2026 As of August 18, 2026, Malcolm is affected by vulnerabilities in the following product: Malcolm Prior to 26.06.1 (CVE-2026-55676) Prior to 26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Prior to or equal to 26.07.1 (CVE-2026-19670, CVE-2026-19671) The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CISA Malcolm | CISA ICS Advisories | CISA
CSIRTS triage
- What
- Multiple unspecified vulnerabilities in Malcolm prior to versions 26.06.1, 26.07.0, and 26.07.1.
- Who is affected
- Systems running Malcolm versions prior to 26.06.1, 26.07.0, or 26.07.1.
- Urgency
- Unknown — advisory provides limited technical detail; check Malcolm project documentation for severity.
- Action
- Update Malcolm to version 26.06.1, 26.07.0, or later as appropriate.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Malcolm
Get an email when a new Malcolm advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-security-advisory-av26-841
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-556760.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-631330.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-631340.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-631770.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196700.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-196710.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55676 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63133 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63134 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63177 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19670 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19671 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-19671: Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-d…nvd
- mediumCVE-2026-19670: Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated us…nvd
- criticalCISA Malcolmcisa
- highCVE-2026-63177: Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access …nvd
- mediumCVE-2026-63134: Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` …nvd
- mediumCVE-2026-63133: Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` …nvd
- highCVE-2026-55676: Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP back…nvd
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24