THE BLUF
This was a heavy week on the CISA KEV catalog and a critically important one for any water utility that relies on MikroTik routers, Fortinet appliances, Cisco firewall management, or ConnectWise ScreenConnect for remote support — which covers a huge swath of this sector. CISA added 14 new Known Exploited Vulnerabilities between September 8 and September 11, and at least seven of them directly threaten equipment commonly found in small-to-mid-size water utility networks. The most operationally dangerous: two MikroTik RouterOS vulnerabilities (CVE-2026-86060 and CVE-2026-67277) — one a command injection, the other a missing authentication flaw — are confirmed actively exploited. MikroTik routers are cheap, ubiquitous in small utility networks, and frequently sit at the IT/OT boundary carrying traffic between the business network and SCADA systems. If your MikroTik hasn't been updated, an attacker can walk through the front door without credentials. Separately, a Fortinet heap-based buffer overflow (CVE-2025-25249) affecting multiple products was added on September 9 — if your FortiGate is your perimeter firewall, this is a patch-now item. A Cisco Firewall Management Center authentication bypass (CVE-2026-20079) and a ConnectWise ScreenConnect privilege management flaw (CVE-2026-84869) round out the urgent list. Meanwhile, no new water-sector-specific advisories were published by CISA or EPA in the past 7 days. On the compliance clock: utilities serving 3,301–49,999 people now have fewer than 16 weeks until the December 31, 2026 deadline for updated Emergency Response Plans under AWIA. Every week you delay increases the cost and the risk of a rushed, incomplete filing.
THREAT INTELLIGENCE
🟠 [CRITICAL VULNERABILITY] MikroTik RouterOS — Dual Active Exploitation (CVE-2026-86060 & CVE-2026-67277)
On September 10, 2026, CISA added two MikroTik RouterOS vulnerabilities to the KEV catalog. CVE-2026-86060 is an improper neutralization of argument delimiters in a command vulnerability — effectively a command injection flaw. CVE-2026-67277 is a missing authentication for critical function vulnerability, meaning an attacker can access administrative functions on the router without any credentials at all. Both are confirmed actively exploited. MikroTik routers are widely deployed at small water and wastewater utilities as edge routers, wireless backhaul devices between remote sites and the main plant, and VLAN trunk switches. They are often the only network device standing between the SCADA LAN and the internet or between a remote well site and the treatment plant. The missing authentication flaw means no brute force or stolen password is required — the attacker simply accesses the management interface directly. The command injection flaw then allows arbitrary code execution on the device itself. For utilities where the MikroTik router is the sole perimeter device or the device bridging remote telemetry (e.g., RTUs at booster stations) back to the central SCADA host, compromise of this device gives an attacker direct access to the OT network and the ability to intercept or manipulate control traffic.
Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] Fortinet Multiple Products — Heap-Based Buffer Overflow (CVE-2025-25249)
On September 9, 2026, CISA added CVE-2025-25249 to the KEV catalog. This is a heap-based buffer overflow affecting multiple Fortinet products, confirmed actively exploited. Fortinet FortiGate firewalls are among the most common perimeter security appliances at water utilities of all sizes. A heap-based buffer overflow in a perimeter firewall allows a remote attacker to execute arbitrary code or crash the device — either outcome is catastrophic for a utility that depends on that single appliance for all network segmentation between IT, OT, and the internet. If the appliance crashes, the utility may lose all remote visibility into SCADA until someone physically drives to the plant.
Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] ConnectWise ScreenConnect — Privilege Management and Missing Authorization (CVE-2026-84869)
On September 11, 2026, CISA added CVE-2026-84869 to the KEV catalog. This is an improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect, confirmed actively exploited. ScreenConnect is one of the most widely used remote support tools in the water sector — SCADA integrators, managed service providers (MSPs), and IT contractors use it to remotely access HMI workstations, PLCs, and historian servers. A privilege escalation flaw in this tool means an attacker who gains even low-level access to a ScreenConnect session can elevate to full administrative control of the connected endpoint. Because ScreenConnect sessions often bridge directly into OT environments, exploitation of this vulnerability gives an adversary the same access your integrator has — which is typically full, unrestricted access to SCADA.
Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] Cisco Firewall Management Center — Authentication Bypass (CVE-2026-20079)
On September 9, 2026, CISA added CVE-2026-20079 to the KEV catalog. This is an authentication bypass using an alternate path or channel vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management, confirmed actively exploited. Cisco FMC is the centralized management platform for Cisco firewalls — the console where firewall rules, access policies, and network segmentation are configured and enforced. An authentication bypass on this platform means an attacker can modify firewall rules, open ports, or disable security policies without legitimate credentials. For a utility using Cisco firewalls to segment their IT and OT networks, this vulnerability effectively allows an adversary to silently remove the barriers between those networks.
Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] Microsoft Windows — Two Actively Exploited Vulnerabilities (CVE-2026-81963 & CVE-2026-85880)
On September 8, 2026, CISA added two Microsoft Windows vulnerabilities to the KEV catalog. CVE-2026-81963 is a link-following vulnerability and CVE-2026-85880 is a heap-based buffer overflow, both confirmed actively exploited. Every Windows-based HMI workstation, SCADA server, historian, and operator laptop in your plant is potentially affected. The link-following vulnerability can be exploited to escalate privileges or access protected files, while the heap-based buffer overflow can allow code execution. In flat utility networks where Windows machines have direct line-of-sight to PLCs and RTUs, exploitation of either flaw gives an attacker a foothold that is one hop away from process control.
Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] Google Chromium V8 — Out of Bounds Write (CVE-2026-87491)
On September 9, 2026, CISA added CVE-2026-87491 to the KEV catalog. This is an out-of-bounds write vulnerability in Google Chromium V8, confirmed actively exploited. This is a different vulnerability from the Chrome V8 type confusion flaw (CVE-2026-85046) covered last week — this is a new, separate V8 exploit. An out-of-bounds write in the browser's JavaScript engine can be triggered by visiting a malicious web page and results in arbitrary code execution on the machine. At water utilities, Chrome is the default browser on most workstations. If an operator clicks a phishing link or a compromised vendor email on an HMI workstation, this vulnerability can deliver full code execution — no additional user interaction required.
Source: CISA KEV Catalog
🔴 [REGULATORY MANDATE] AWIA Compliance Clock — ERP Deadline Now Under 16 Weeks
No new EPA guidance was published in the past 7 days. The compliance deadlines remain unchanged and continue to approach:
Utilities serving 3,301–49,999 people: Recertified Risk and Resilience Assessments (RRAs) are due June 30, 2026 — that deadline has already passed. Updated Emergency Response Plans (ERPs) are due December 31, 2026 — now fewer than 16 weeks away.
Utilities serving 50,000–99,999 people: Updated ERPs were due June 30, 2026 — that deadline has already passed. Confirm your certifications are filed.
🔒 PREMIUM TIER BOUNDARY In our standard free dispatch, the briefing concludes here. The following sections—The Action Plan, The KEV Compliance Checklist, The Tabletop Exercise, and the physical Attestation Log—are strictly reserved for Premium Subscribers. We have fully unlocked this Vol. 1, Issue 25 edition to demonstrate the exact, audit-ready intelligence our members use every week to secure their facilities and maintain regulatory compliance.
THE ACTION PLAN
🟠 [CRITICAL VULNERABILITY] MikroTik RouterOS — Dual Active Exploitation (CVE-2026-86060 & CVE-2026-67277)
☐ Immediately change the default admin password on every MikroTik device. If you are still using the factory-default "admin" account with no password, you are compromised right now — assume it and act accordingly.
☐ Disable all internet-facing management interfaces (Winbox, WebFig, SSH, API) on every MikroTik router. If remote management is required, restrict access to a specific allowlisted IP address (your office, your IT contractor) via firewall rules on the device itself.
☐ Disable unused services and ports — MikroTik ships with numerous services enabled by default (FTP, Telnet, API, BandwidthServer). Turn off anything you are not actively using.
☐ Update RouterOS to the latest stable firmware immediately. Check for updates via the MikroTik Winbox "System > Packages" menu. If the router is too old to accept current firmware, it must be replaced.
☐ Consider isolating any MikroTik device that sits at the IT/OT boundary by placing a dedicated firewall between it and the SCADA/control network. If budget does not allow an additional firewall, consider severing the MikroTik's direct connection to the OT VLAN and temporarily running on manual operations at remote sites until patching is confirmed.
☐ Review MikroTik device logs for any unexpected admin sessions, configuration changes, or new user accounts created in the past 30 days.
☐ Reminder: CISA offers free vulnerability scanning and assessment services — request a scan of your perimeter if you are unsure what is exposed.
Source: NVD CVE-2026-86060 | NVD CVE-2026-67277
🟠 [CRITICAL VULNERABILITY] Fortinet Multiple Products — Heap-Based Buffer Overflow (CVE-2025-25249)
☐ Verify MFA is enabled on all FortiGate management interfaces. This is free and should already be done.
☐ Restrict management access to the FortiGate from the LAN only — do not expose the management GUI or SSH to the WAN/internet interface. If your IT contractor needs remote management access, require them to VPN in first.
☐ Apply the Fortinet security patch for CVE-2025-25249 immediately. Check the Fortinet support portal for the specific firmware version that addresses this CVE for your product model.
☐ If patching cannot be completed within 48 hours, consider temporarily severing the FortiGate's WAN-facing connection and operating on manual/local network only until the patch is applied. This is disruptive but preferable to compromise.
☐ Review FortiGate logs for unexpected configuration changes, admin logins from unknown IPs, or new VPN tunnels in the past 30 days.
Source: NVD CVE-2025-25249
🟠 [CRITICAL VULNERABILITY] ConnectWise ScreenConnect — Privilege Management and Missing Authorization (CVE-2026-84869)
☐ Immediately audit all ScreenConnect user accounts — remove any accounts that do not belong to an active, authorized technician. Remove default or generic accounts.
☐ Enable MFA on all ScreenConnect accounts — this is a free configuration change and is the single most effective mitigation.
☐ Update ScreenConnect to the latest version from ConnectWise. Confirm with your SCADA integrator or MSP that their instance is also patched — if they use a cloud-hosted instance, verify with them directly.
☐ If your integrator uses ScreenConnect to access OT/SCADA hosts, require that ScreenConnect sessions be initiated only during scheduled maintenance windows and that sessions are terminated when not actively in use. Do not leave persistent unattended access sessions running.
☐ Consider severing persistent ScreenConnect agents from OT workstations entirely and switching to a session-only (attended) access model where an operator must physically approve each connection at the HMI.
Source: NVD CVE-2026-84869
🟠 [CRITICAL VULNERABILITY] Cisco Firewall Management Center — Authentication Bypass (CVE-2026-20079)
☐ Restrict network access to the FMC management interface — ensure it is not reachable from the internet or from any untrusted network segment. Limit access to a dedicated management VLAN accessible only from authorized admin workstations.
☐ Enable MFA for all FMC administrative accounts if supported by your deployment.
☐ Apply the Cisco security patch for CVE-2026-20079. Check Cisco's Security Advisory portal for the specific FMC software version that remediates this CVE.
☐ Review FMC audit logs for any unauthorized policy changes, new access rules, or administrative logins from unrecognized sources in the past 30 days.
☐ If FMC cannot be patched immediately, consider isolating it from the network entirely and managing firewalls via local console access until the patch is applied.
Source: NVD CVE-2026-20079
🟠 [CRITICAL VULNERABILITY] Microsoft Windows — Two Actively Exploited Vulnerabilities (CVE-2026-81963 & CVE-2026-85880)
☐ Apply the latest Microsoft security updates (September Patch Tuesday) to all Windows machines — prioritize HMI workstations, SCADA servers, and historian servers. If you have a WSUS server, push updates immediately.
☐ For any Windows-based OT workstation that cannot be patched immediately due to vendor compatibility requirements, consider isolating it from the broader network by disabling its internet access and restricting its communications to only the PLCs/RTUs it must talk to.
☐ Ensure Windows workstations in the OT environment are not used for general web browsing or email. Dedicate them solely to SCADA operations.
☐ If your OT environment still runs end-of-life Windows versions (Windows 7, Server 2008), these systems will not receive patches. Consider air-gapping them completely or planning for replacement.
Source: NVD CVE-2026-81963 | NVD CVE-2026-85880
🟠 [CRITICAL VULNERABILITY] Google Chromium V8 — Out of Bounds Write (CVE-2026-87491)
☐ Update Google Chrome to the latest version on every machine in your environment — HMI workstations, operator laptops, office PCs, and historian servers. Chrome auto-updates if the browser is restarted, but many OT workstations run 24/7 without a browser restart.
☐ On HMI and SCADA workstations, restrict Chrome to only the URLs required for operations (e.g., the HMI web interface, the historian dashboard). Use Chrome's managed browser policies to block all other web navigation.
☐ Remind all staff: do not click links in unsolicited emails, even from known vendors. Phishing is the primary delivery mechanism for browser-based exploits.
Source: NVD CVE-2026-87491
🔴 [REGULATORY MANDATE] AWIA Compliance Clock — ERP Deadline Now Under 16 Weeks
☐ Utilities serving 3,301–49,999 people: If you have not begun your updated Emergency Response Plan, start now. The ERP must incorporate the findings from your recertified RRA (which was due June 30, 2026). Your updated ERP is due December 31, 2026.
☐ Utilities serving 50,000–99,999 people: Your updated ERP was due June 30, 2026. If you have not certified, contact your EPA regional office immediately to discuss compliance.
☐ If you need free technical assistance for your RRA or ERP, contact WaterISAC (Member Login Required) or request a free cybersecurity assessment through CISA's no-cost cyber services.
☐ If you experience a qualifying cyber incident while preparing your AWIA documentation, remember that under CIRCIA, the 72-hour reporting clock begins the moment you "reasonably believe" a qualifying cyber incident has occurred. Ransomware payments must be reported within 24 hours.
THE KEV COMPLIANCE CHECKLIST
🟠 [CRITICAL VULNERABILITY] Citrix NetScaler — Authentication Bypass (CVE-2026-19490)
Added to the KEV catalog on September 9, 2026. This is an authentication bypass using an alternate path or channel vulnerability in Citrix NetScaler, confirmed actively exploited. While NetScaler is less common in small utilities, some mid-size utilities and shared-services regional water authorities use Citrix for remote desktop access or application delivery.
☐ Disable any internet-facing NetScaler Gateway or management interface immediately if patching cannot be completed within 48 hours.
☐ Audit all NetScaler virtual servers and Gateway configurations for unauthorized changes.
☐ Apply the Citrix security patch for CVE-2026-19490 from the Citrix support portal.
☐ If your utility does not use Citrix NetScaler, no action is required — but verify with your IT contractor that they are not using it to provide remote services to your environment.
☐ Reminder: EPA and CISA offer free cybersecurity assessments to help identify exposed services like NetScaler on your network perimeter.
Source: NVD CVE-2026-19490
THE TABLETOP EXERCISE
Scenario: "The Router Nobody Remembers"
It's 6:15 AM on a Monday. Your lead operator calls in to say that the remote telemetry from three booster pump stations and one elevated storage tank has gone dark overnight — no readings, no alarms, no communication. Your SCADA system shows all four remote sites as "communication failure." Your IT contractor investigates and discovers that the MikroTik router at your main plant — the device that routes all radio/cellular backhaul traffic from remote sites — has been compromised. The router's admin password was the factory default. The attacker has modified routing tables to redirect all SCADA traffic through an external IP address, and the router's firmware has been replaced with a modified version. The IT contractor says the router cannot be trusted and must be replaced. You have no spare MikroTik on hand. Your distributor says 3–5 business day lead time for a replacement. Your four remote sites are blind — you have no tank levels, no pump status, no pressure readings, and no ability to remotely start/stop pumps.
Discussion Questions:
☐ You have no remote visibility into four sites. What is your manual operations plan for maintaining water pressure and tank levels for the next 3–5 days? Who drives to each site, how often, and what manual readings do they take? Do you have the physical keys and access codes for all four sites?
☐ Your SCADA traffic was being redirected to an unknown external IP. Under CIRCIA, when does your 72-hour reporting clock begin — when the operator noticed the outage, or when the IT contractor confirmed the compromise? Who at your utility is authorized to make the "reasonable belief" determination, and do they have the reporting contact information readily accessible?
☐ Your compromised MikroTik router was using the factory default password and had its management interface exposed to the internet. When the replacement arrives, what specific hardening steps will you require before it is connected to the network, and how will you document those steps to satisfy your AWIA Emergency Response Plan?
Stay secure and stay compliant,
The Reinforcefy Team
Weekly Compliance Attestation & Audit Log
(To be completed by the designated facility manager or IT supervisor)
Briefing Issue: Vol. 1, Issue 25 | Date Reviewed: ........................
Actions Executed / IT Tickets Attached:
1. .................................................................
2. .................................................................
3. .................................................................
By signing below, I attest that I have reviewed this week’s intelligence briefing, delegated or completed the applicable technical remediations noted above, and attached the necessary supporting artifacts to this physical audit record.
Authorized Signature:
........................................................
Printed Name & Title:
........................................................
