CISAMalcolmnetwork-traffic-analysisRCEpath-traversalauthorization-bypassdenial-of-servicefile-uploadRBAC-bypasszip-bombagent-relevant
Multiple vulnerabilities have been disclosed in CISA's Malcolm network traffic analysis tool suite, including an unauthenticated-adjacent arbitrary PHP code execution flaw (CVE-2026-55676, CVSS 8.8), two nginx/Lua RBAC bypasses via URI normalization mismatches (CVE-2026-63177, CVE-2026-19670), a path traversal in archive extraction (CVE-2026-63134), and two resource-exhaustion/DoS flaws involving malicious archives and decompression bombs (CVE-2026-63133, CVE-2026-19671). Versions prior to 26.06.1/26.07.0/26.08.0 depending on the specific CVE are affected, with vendor patches available and no known public exploitation reported at this time.
Updated Aug 19, 2026 · CVSS 8.8