Multiple Security Flaws Found in CISA's Malcolm Network Monitoring Tool
CISA has published an advisory detailing multiple vulnerabilities affecting Malcolm, a widely used open-source network traffic analysis tool. The flaws affect versions prior to 26.06.1, 26.07.0, and up to 26.07.1, and include issues such as unrestricted resource use, path traversal, unrestricted file uploads, incorrect authorization, and mishandling of highly compressed data.
With a CVSS score of 8.8, these vulnerabilities are rated high severity. If exploited, an attacker could cause a denial-of-service condition, disrupting network monitoring capabilities, or potentially execute arbitrary code on affected systems. Malcolm is used across the Information Technology sector worldwide, meaning organisations relying on it for network visibility and security monitoring should treat this advisory seriously.
While Malcolm is more commonly deployed by larger IT and security teams, Australian small businesses that use managed security providers or third-party network monitoring tools should confirm with their providers whether any underlying components are affected. Patching promptly and verifying vendor updates remains the most effective defence against these types of vulnerabilities.