cisagov has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was August 2026 with 4. The median CVSS is 6.8 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
cisagov vulnerabilities
CVEs affecting cisagov, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-63177High· 7.1Malcolm is a network traffic analysis tool suite
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests usi…
CVE-2026-63134Medium· 5.4PoCMalcolm is a network traffic analysis tool suite
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathnam…
CVE-2026-63133Medium· 6.5PoCMalcolm is a network traffic analysis tool suite
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a…
CVE-2026-55676High· 8.8Malcolm is a network traffic analysis tool suite
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-l…