VulnSea

CISA has 15 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 15. The median CVSS is 6.9 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.9
Publish → KEV
Last 90 days
15 prev 0

Products

  • Malcolm 15
15
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

CISA vulnerabilities

CVEs affecting CISA, newest first. Open any entry for full detail, references, and exploit status.

15 CVEsRSS

CVE-2026-90457Medium· 6.9
1w ago

The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local …

The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local …

SunlitCISA · MalcolmEPSS 0.09%via NVD
CVE-2026-90456Critical· 9.2
1w ago

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the s…

MidnightCISA · MalcolmEPSS 0.25%via NVD
CVE-2026-90455Medium· 6.3
1w ago

A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component

A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that compone…

SunlitCISA · MalcolmEPSS 0.22%via NVD
CVE-2026-90454Medium· 5.3
1w ago

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, …

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, …

SunlitCISA · MalcolmEPSS 0.21%via NVD
CVE-2026-90453Medium· 5.1
1w ago

A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin

A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craf…

SunlitCISA · MalcolmEPSS 0.22%via NVD
CVE-2026-90452Medium· 6.0
1w ago

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the…

SunlitCISA · MalcolmEPSS 0.09%via NVD
CVE-2026-90451High· 8.2
1w ago

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration w…

TwilightCISA · MalcolmEPSS 0.33%via NVD
CVE-2026-90445High· 7.1
1w ago

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attack…

TwilightCISA · MalcolmEPSS 0.35%via NVD
CVE-2026-90444High· 8.7
1w ago

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, all…

TwilightCISA · MalcolmEPSS 0.23%via NVD
CVE-2026-90443Medium· 5.3
1w ago

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a lin…

SunlitCISA · MalcolmEPSS 0.32%via NVD
CVE-2026-90450Medium· 5.3
1w ago

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered…

SunlitCISA · MalcolmEPSS 0.22%via NVD
CVE-2026-90449Medium· 6.9
1w ago

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. A…

SunlitCISA · MalcolmEPSS 0.31%via NVD
CVE-2026-90448High· 7.1
1w ago

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwr…

TwilightCISA · MalcolmEPSS 0.21%via NVD
CVE-2026-90447High· 7.1
1w ago

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user i…

TwilightCISA · MalcolmEPSS 0.27%via NVD
CVE-2026-90446Medium· 5.3
1w ago

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows …

SunlitCISA · MalcolmEPSS 0.21%via NVD
CISA vulnerabilities (CVEs) · VulnSea