CISA Malcolm ships 15 flaws, patch urged
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CISA's own Malcolm network-traffic analysis tool has 15 vulnerabilities including unauthenticated XSS, command injection, and auth bypass; update to v26.06.0+.
CISA published an ICS advisory for Malcolm, its open-source network traffic analysis tool used across Energy, Information Technology, and Water/Wastewater sectors worldwide. Versions prior to v26.06.0 contain 15 distinct vulnerabilities spanning unauthenticated reflected XSS/open redirect in the web interface, OS command injection via unsanitized uploaded filenames, path traversal during archive extraction, SSRF through unvalidated backend path interpolation, authentication bypass via a client-controlled routing header, missing authorization on read-only deployment modes allowing record forgery and tag tampering, missing authentication for a bundled admin interface that gates the credential store, a fail-open authorization default for unregistered request handlers, hardcoded default secrets/credentials in example configuration files (session-signing key and an inventory component's admin password), weak password hashing with world-readable permissions, a reverted dependency reintroducing a known-vulnerable HTTP client library, and missing TLS certificate validation between the reverse proxy and the identity provider.
Chained together, several of these flaws could allow an unauthenticated or low-privileged attacker to escalate to administrative control, exfiltrate or tamper with ingested log/session data, pivot into internal networks, or forge authentication tokens. CISA reports no known public exploitation at this time. All issues are fixed in Malcolm's September 2026 release (v26.06.0+); the TLS-verification fix additionally requires administrators to manually set KEYCLOAK_SSL_VERIFY, as it is not enabled by default even after patching.
Defenders running Malcolm should prioritize upgrading immediately, rotate any credentials or secrets that may have been copied from example configuration files without regeneration, verify file permissions on password hash stores, and explicitly enable KEYCLOAK_SSL_VERIFY where the identity provider is not on a fully trusted network segment. Standard ICS guidance applies: minimize internet exposure, segment control system networks from business networks, and use VPNs with awareness of their own risks for remote access.
Mentioned in this report
Detection guidance
Web/Upload Handler Spawning Shell With Metacharacters in Pcap Filename
Python/WSGI/web server process spawning a shell whose command line has a pcap/archive filename combined with command-substitution or separator metacharacters, consistent with OS command injection via uploaded filenames (Malcolm-style). Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Web/Upload Handler Spawning Shell With Metacharacters in Pcap Filename
id: 46c7bf0d-7caa-5183-a4a0-7ec6d387eb94
status: experimental
description: Detects a Python/WSGI/web server process spawning a shell whose command
line contains a capture or archive filename together with command substitution or
command separators. This is consistent with OS command injection through unsanitized
uploaded filenames, as in the Malcolm advisory. Applies to Linux hosts or containers
with process telemetry.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
tags:
- attack.execution
- attack.t1059
- attack.initial-access
- attack.t1190
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- /python
- /python3
- /gunicorn
- /uwsgi
- /nginx
- /apache2
- /httpd
- /php-fpm
selection_shell:
Image|endswith:
- /sh
- /bash
- /dash
selection_file:
CommandLine|contains:
- .pcap
- .pcapng
- .zip
- .tar
selection_meta:
CommandLine|contains:
- $(
- '`'
- ;
- '&&'
- '||'
condition: selection_parent and selection_shell and selection_file and selection_meta
falsepositives:
- Legitimate upload-processing scripts that chain commands with ; or && after handling
a pcap or archive file
- Administrators running pcap processing wrappers from a Python service
level: medium
author: Vorant
Web Application Process Spawning Shell With Download or Reverse Shell Primitives
Web server or Python application process spawning a shell that runs curl/wget piped to a shell, netcat, or /dev/tcp redirection, indicating post-exploitation after injection or exploit of a public-facing application. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Web Application Process Spawning Shell With Download or Reverse Shell Primitives
id: 2e504a19-feef-5add-86e2-58d280d04d83
status: experimental
description: Detects web server or Python application processes spawning a shell that
fetches and executes remote content or opens a reverse shell. Fits post-exploitation
following command injection in public-facing analysis or admin web interfaces such
as Malcolm. Applies to Linux hosts or containers with process telemetry.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
tags:
- attack.initial-access
- attack.t1190
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- /python
- /python3
- /gunicorn
- /uwsgi
- /nginx
- /apache2
- /httpd
- /php-fpm
selection_shell:
Image|endswith:
- /sh
- /bash
- /dash
selection_payload:
CommandLine|contains:
- /dev/tcp/
- bash -i
- nc -e
- ncat -e
- '| sh'
- '| bash'
- '|sh'
- '|bash'
condition: selection_parent and selection_shell and selection_payload
falsepositives:
- Application health checks or installer scripts that pipe a downloaded script to
a shell from a Python service
- Containerized deployment tooling that bootstraps components via curl piped to sh
level: high
author: Vorant
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,566 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs