Back to Intelligence

ICSA-26-254-01: CISA Malcolm CVSS 8.8 Web Flaws — Isolate, Patch, and Hunt Guide

SA
Security Arsenal Team
October 1, 2026
10 min read

CISA has published an ICS advisory for CISA Malcolm under ICSA-26-254-01 with a CVSS v3 score of 8.8 (High). The advisory summary lists a stacked set of web and platform weaknesses: cross-site scripting, OS command injection, path traversal, SSRF, authentication bypass by spoofing, missing authorization, missing authentication for critical functions, incorrect authorization, default credentials, improper certificate validation, open redirect, vulnerable third-party components, and insufficient password hashing.

This matters because Malcolm is not a business convenience app; it is commonly deployed as a network traffic analysis and sensor-management platform near OT/ICS visibility points. If the Malcolm web tier, API, bundled dependencies, or management interfaces are reachable by an attacker—or by an already-compromised IT host—the impact is not limited to the web UI. It can expose captured traffic, sensor configuration, credentials, pcap artifacts, network metadata, and in worst cases provide a foothold adjacent to monitored ICS segments.

The urgency is high even before exploitation confirmation: a CVSS 8.8 composite with command injection, auth bypass, SSRF, default credentials, and weak certificate validation is the kind of defect cluster that turns a monitoring node into a pivot. Treat exposed Malcolm instances as priority remediation assets and validate exact affected builds against the CSAF attached to ICSA-26-254-01.

Technical Analysis

Affected products and scope

  • Vendor: CISA
  • Product/equipment: CISA Malcolm
  • Advisory: ICSA-26-254-01
  • Severity: CVSS v3 8.8 / High
  • Affected versions: The provided advisory summary identifies “Malcolm” but does not enumerate exact version strings in the excerpt. Do not assume only one release is affected. Inventory every Malcolm deployment, container tag, git checkout/commit, appliance build, and downstream fork, then compare against the CSAF document and release notes referenced by ICSA-26-254-01 before declaring any instance out of scope.

Malcolm deployments are typically Linux/Docker-based and may expose several trust boundaries: an HTTPS reverse proxy/UI, authentication components, search/index services, protocol parsers, file upload/pcap processing paths, sensor update channels, and third-party images. The vulnerability classes listed imply defects across more than one layer, so a single “restart the web container” action is not a remediation strategy.

Vulnerability classes and defender-relevant attack chains

The advisory summary does not provide CVE identifiers in the excerpt, and I am not assigning any. The defensive model should therefore focus on observable behavior and reachable exposure rather than a single CVE.

Likely defender scenarios to plan for:

  • OS command injection via web/API input: a crafted request to a Malcolm web/API endpoint reaches a shell, interpreter, or utility in a container/host. Observable outcome: nginx/Apache/node/python/php/java-adjacent processes spawning sh, bash, dash, curl, wget, nc, socat, perl, or interpreters with suspicious arguments.
  • Path traversal against upload, pcap, config, log, or artifact handlers: requests containing ../, encoded variants, absolute paths, or attempts to read /etc/passwd, .env, Docker compose files, TLS keys, session stores, or captured artifacts.
  • SSRF from Malcolm services: the platform is induced to fetch internal URLs, cloud metadata (169.254.169.254), localhost services, Docker socket proxies, OpenSearch/Elasticsearch, Arkime, Keycloak/IdP endpoints, NetBox-like inventory services, or sensor management APIs.
  • Authentication/authorization failures: spoofable headers, missing authZ checks on API routes, unauthenticated critical functions, or role confusion exposing administrative actions, sensor control, credential views, or PCAP download.
  • Default credentials / weak hashing: stale .env, compose, or image defaults; reused admin passwords; unsalted or fast hashes enabling offline cracking if auth stores are copied.
  • Improper certificate validation / open redirect / vulnerable dependencies: update or integration paths that trust attacker-controlled TLS, redirect users to credential-harvesting pages, or ship vulnerable packages inside containers.

Exploitation status

A CISA advisory publication is not automatically proof of active exploitation or KEV inclusion. As of this post, use ICSA-26-254-01 and its CSAF as the source of truth for affected versions, fixed releases, mitigations, and any stated exploitation notes. Separately check the current CISA KEV catalog before assigning BOD-style deadlines. Operationally, do not wait for KEV to reduce exposure on a monitoring platform with this defect mix.

Detection & Response

Sigma

YAML
---
title: CISA Malcolm Web Tier Spawning Shell or Egress Tool
tid: 9f2c7a11-6d3b-4c9f-a812-0f4d8c2a7b51
status: experimental
description: Detects possible command-injection or post-exploitation where web, proxy, interpreter, or container-adjacent processes on Malcolm hosts spawn shells or network egress tools.
references:
  - https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
  - https://attack.mitre.org/techniques/T1059/
  - https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/09/12
tags:
  - attack.execution
  - attack.t1059
  - attack.command_and_control
  - attack.t1105
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|contains:
      - '/nginx'
      - '/apache2'
      - '/httpd'
      - '/node'
      - '/python'
      - '/php'
      - '/java'
      - 'containerd'
      - 'dockerd'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/dash'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
      - '/socat'
      - '/perl'
      - '/python'
      - '/python3'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate container health checks and controlled maintenance scripts
  - Backup or log-shipping jobs using curl under a known service account
level: high
---
title: CISA Malcolm Traversal or SSRF Indicators in Web or Proxy Requests
tid: 4db7e2a0-91ac-4d5e-9c31-6a1b0d8f2e44
status: experimental
description: Detects HTTP requests consistent with path traversal, local file read, localhost/internal SSRF, or command metacharacters targeting Malcolm-related web services.
references:
  - https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
  - https://attack.mitre.org/techniques/T1190/
  - https://attack.mitre.org/techniques/T1083/
author: Security Arsenal
date: 2026/09/12
tags:
  - attack.initial_access
  - attack.t1190
  - attack.discovery
  - attack.t1083
logsource:
  category: proxy
detection:
  selection_uri:
    url|contains:
      - '../'
      - '..\\'
      - '%2e%2e'
      - '%252e%252e'
      - '/etc/passwd'
      - '/proc/self/environ'
      - '.env'
      - 'docker-compose'
      - '169.254.169.254'
      - '127.0.0.1'
      - 'localhost'
      - '0.0.0.0'
      - ';id'
      - '|id'
      - '&&id'
      - '%3bid'
      - '%7cid'
  selection_malcolm:
    url|contains:
      - 'malcolm'
      - 'arkime'
      - 'opensearch'
      - 'elasticsearch'
      - 'keycloak'
      - 'netbox'
      - 'pcap'
      - 'upload'
      - 'api'
  condition: selection_uri and selection_malcolm
falsepositives:
  - Scanner traffic already blocked upstream; still useful for exposure validation
  - Red-team exercises against a lab Malcolm instance
level: medium

KQL — Microsoft Sentinel / Defender

Use this where Malcolm hosts forward syslog, nginx/proxy logs, Zeek/Suricata logs, or CEF to Sentinel. It prioritizes request-level traversal/SSRF and suspicious child-process telemetry ingested from Linux auditd or Defender for Endpoint.

KQL — Microsoft Sentinel / Defender
let Lookback = 14d;
let MalcolmTokens = dynamic(["malcolm","arkime","opensearch","elasticsearch","keycloak","netbox","pcap","upload","api"]);
let BadUri = dynamic(["../","..\\","%2e%2e","%252e%252e","/etc/passwd","/proc/self/environ",".env","docker-compose","169.254.169.254","127.0.0.1","localhost","0.0.0.0",";id","|id","&&id","%3bid","%7cid"]);
union isfuzzy=true (Syslog | project TimeGenerated, Computer, ProcessName, SyslogMessage), (CommonSecurityLog | project TimeGenerated, DeviceName=Computer, ProcessName, SyslogMessage=Message)
| where TimeGenerated >= ago(Lookback)
| extend Msg = coalesce(SyslogMessage, "")
| where Msg has_any (MalcolmTokens) and Msg has_any (BadUri)
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Hits=count(), Sample=any(Msg) by Computer, ProcessName
| order by Hits desc;
DeviceProcessEvents
| where TimeGenerated >= ago(Lookback)
| where InitiatingProcessFileName has_any ("nginx","apache2","httpd","node","python","php","java","containerd","dockerd")
   or InitiatingProcessCommandLine has_any ("nginx","apache2","httpd","node","python","php","java","containerd","dockerd")
| where FileName in~ ("sh","bash","dash","curl","wget","nc","ncat","socat","perl","python","python3")
   or ProcessCommandLine has_any ("169.254.169.254","127.0.0.1","/etc/passwd",".env","curl http","wget http","bash -i","nc -e","socat")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName, FolderPath
| order by TimeGenerated desc;
DeviceNetworkEvents
| where TimeGenerated >= ago(Lookback)
| where LocalPort in (443, 8000, 8080, 8443, 9200, 9300, 5601, 5044)
   and (LocalIP == "0.0.0.0" or LocalIP == "::")
| project TimeGenerated, DeviceName, LocalIP, LocalPort, RemoteIP, RemotePort, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by TimeGenerated desc;

Velociraptor VQL

Run on Malcolm hosts/sensors to identify shell or egress-tool execution consistent with web-tier compromise, plus unexpectedly broad listeners for management/search services.

VQL — Velociraptor
-- Suspicious child processes and broad listeners on CISA Malcolm hosts
LET suspicious_procs = SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE (Name =~ '^(sh|bash|dash|curl|wget|nc|ncat|socat|perl|python|python3)$' OR Exe =~ '/(tmp|var/tmp|dev/shm)/')
  AND (CommandLine =~ '169\.254\.169\.254|127\.0\.0\.1|/etc/passwd|/proc/self/environ|\.env|docker-compose|curl http|wget http|bash -i|nc -e|socat'
       OR Exe =~ '/(tmp|var/tmp|dev/shm)/');

LET broad_listeners = SELECT Pid, Name, LocalAddr, LocalPort, RemoteAddr, RemotePort, Status
FROM netstat()
WHERE Status =~ 'LISTEN'
  AND LocalAddr =~ '^(0\.0\.0\.0|::|:::)$'
  AND LocalPort in (443, 8000, 8080, 8443, 9200, 9300, 5601, 5044);

SELECT * FROM suspicious_procs;
SELECT * FROM broad_listeners;

Bash — exposure verification and safe hardening helper

This script is deliberately non-destructive by default. Set APPLY=1 only after backups, change control, and confirmation of the fixed release from the CSAF.

Bash / Shell
#!/usr/bin/env bash
set -euo pipefail
MODE="${APPLY:-0}"
FIXED_TAG="${FIXED_TAG:-<FIXED_TAG_FROM_CSAF>}"
REPORT="malcolm_exposure_$(date +%Y%m%d_%H%M%S).txt"
{
echo "== CISA Malcolm ICSA-26-254-01 exposure check =="
date -u
hostname
if command -v git >/dev/null 2>&1 && [ -d .git ]; then
  echo "-- git --"; git remote -v || true; git describe --tags --always --dirty || true; git log -1 --oneline || true
fi
if command -v docker >/dev/null 2>&1; then
  echo "-- docker compose images --"; docker compose images 2>/dev/null || docker-compose images 2>/dev/null || true
  echo "-- running containers --"; docker ps --format 'table {{.Names}}\t{{.Image}}\t{{.Ports}}\t{{.Status}}' || true
fi
echo "-- listening sockets --"; ss -lntup 2>/dev/null || netstat -lntup 2>/dev/null || true
echo "-- risky public bindings --"; ss -lnt 2>/dev/null | awk 'NR==1 || /0\.0\.0\.0|:::|\*/' | grep -E ':(443|8000|8080|8443|9200|9300|5601|5044)\b' || true
echo "-- default/env credential hints --"; grep -RInE '(^|_)(PASSWORD|PASSWD|TOKEN|SECRET|APIKEY|API_KEY|ADMIN|DEFAULT)(_|=|:)' .env docker-compose*.yml *.env 2>/dev/null | sed -E 's/=.*/=<redacted>/' || true
echo "-- TLS validation hints --"; grep -RInE 'verify.*false|ssl.*false|insecure|NODE_TLS_REJECT_UNAUTHORIZED|PYTHONHTTPSVERIFY|curl.*-k|wget.*--no-check-certificate' . .env docker-compose*.yml 2>/dev/null | head -200 || true
} | tee "$REPORT"
echo "Report written: $REPORT"
if [ "$MODE" = "1" ]; then
  echo "APPLY mode: review $REPORT, backup configs/pcaps, then upgrade to $FIXED_TAG only if confirmed by ICSA-26-254-01 CSAF."
  echo "Example guarded flow: cp -a .env .env.bak && docker compose pull && docker compose up -d"
else
  echo "Dry run only. Re-run with APPLY=1 and FIXED_TAG=<confirmed fixed tag> after backup and change approval."
fi

Remediation

  1. Confirm scope against the CSAF, not memory. Pull the CSAF attached to ICSA-26-254-01 and record exact affected and fixed version identifiers for every Malcolm instance, including lab, DR, sensor, and offline PCAP analysis nodes. Do not rely on the excerpted summary for final version closure.
  2. Immediately reduce reachability. Malcolm UI/API/search/auth endpoints should never be Internet-facing. Restrict to SOC jump hosts or VPN/ZTNA, enforce source ACLs/security groups, require MFA at the IdP/reverse proxy where architecture supports it, and block direct OT workstation access to management ports unless explicitly required.
  3. Patch and rebuild containers completely. Upgrade to the fixed release/tag listed in the CSAF; pull fresh signed images; rebuild rather than patching binaries inside running containers; remove stale tags and orphaned volumes after verification. Address vulnerable third-party components as part of the image update, not as a separate afterthought.
  4. Rotate secrets and invalidate sessions. Rotate admin, service, API, database/search, IdP/client, sensor, TLS private keys where exposure is plausible, and any default credentials found in .env, compose files, scripts, backups, or documentation. Force logout/token revocation and review active sessions after upgrade.
  5. Enforce egress control from Malcolm. Deny outbound from Malcolm hosts to RFC1918/link-local/metadata unless required; explicitly block 169.254.169.254, localhost abuse from containers, Docker socket exposure, and unneeded Internet fetch. Permit only approved update repos, threat intel feeds, time sync, and SOC destinations.
  6. Harden configuration. Bind management/search/auth services to localhost or a dedicated management interface where possible; disable unauthenticated critical endpoints; require authorization checks on every API route; remove default accounts; use strong unique credentials and modern password hashing; pin valid TLS with strict verification; eliminate verify=false, -k, --no-check-certificate, and HTTP fallback.
  7. Protect captured data. Treat pcaps, Zeek/Suricata logs, extracted files, screenshots, and Arkime sessions as sensitive. Encrypt at rest where supported, restrict download roles, enable audit logging for exports, and review retention to limit blast radius.
  8. Hunt before and after patching. Use the detections above across the last 14–30 days. Look for traversal/SSRF requests, unexpected child processes from web/container parents, listeners re-bound to 0.0.0.0, new local users, modified compose/env files, unexpected image pulls, and outbound connections from Malcolm to internal services it does not normally touch.
  9. If compromise is suspected: isolate the host without destroying evidence, snapshot disks and container state, preserve logs/pcaps and Docker metadata, export auth/search logs, rotate credentials from a clean host, and rebuild from known-good media. Do not simply “update and continue” if web-tier command execution is plausible.
  10. Governance: add Malcolm to the vulnerability-management SLA for High findings, include it in attack surface management and external scans, and require an asset owner, network zone, data classification, and recovery plan for each deployment. Verify current CISA KEV status; if added, apply the associated federal deadline and align internal due dates accordingly.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.