THE BLUF

A relatively quiet week from CISA on the water-sector advisory front — no new water-specific cybersecurity advisories were published in the past 7 days. However, the KEV catalog kept churning: CISA added 11 new Known Exploited Vulnerabilities between August 24 and August 27, and two of them deserve your immediate attention. CVE-2026-8452, a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway, is now confirmed actively exploited. If your utility uses a Citrix appliance for remote access or VPN — and many small-to-mid-size utilities do — an attacker can exploit this flaw to crash the device or gain code execution, severing your operators' remote connectivity to SCADA and forcing manual workarounds at every remote site until the appliance is restored. Separately, CVE-2019-1068, a remote code execution flaw in Microsoft SQL Server, was added to the KEV catalog. Many SCADA historians and data-logging platforms sit on top of SQL Server — if that database is compromised, your process data integrity is gone and your reporting to state regulators may be questioned. On the advisory side, CISA published AA26-237A, "A Tale of Two SOCs," on August 25 — a red team assessment advisory that, while not water-sector-specific, exposes defensive gaps that are painfully common in small utility IT environments. On the compliance calendar: utilities serving 3,301–49,999 people now have fewer than 18 weeks until the December 31, 2026 deadline for updated Emergency Response Plans under AWIA. The clock is ticking.

THREAT INTELLIGENCE

🟡 [ACTIVE THREAT INTEL] CISA Publishes Advisory AA26-237A — "A Tale of Two SOCs: Insights From Two Red Team Assessments"

On August 25, 2026, CISA published Cybersecurity Advisory AA26-237A, documenting lessons learned from two separate red team engagements against critical infrastructure organizations. While this advisory is not water-sector-specific, the defensive failures it documents — insufficient network segmentation, over-reliance on endpoint detection without network monitoring, weak identity management, and failure to detect lateral movement — are the exact failure modes that plague small and mid-size water utilities. The advisory provides real-world evidence of how red team operators moved from an initial IT foothold to deep network access using the same techniques that nation-state actors employ. For water utilities with flat networks where the SCADA workstation sits on the same subnet as the business email server, this advisory is a mirror. Source: CISA Cybersecurity Advisories

🟠 [CRITICAL VULNERABILITY] Citrix NetScaler ADC and NetScaler Gateway — Memory Buffer Vulnerability (CVE-2026-8452)

On August 26, 2026, CISA added CVE-2026-8452 to the KEV catalog. This vulnerability affects Citrix NetScaler ADC and NetScaler Gateway — appliances commonly deployed as VPN gateways, load balancers, and remote access portals. Active exploitation is confirmed. The flaw involves improper restriction of operations within the bounds of a memory buffer, which can allow a remote attacker to crash the appliance or execute arbitrary code. For water utilities, Citrix appliances frequently serve as the single point of remote access for operators, contractors, and SCADA integrators connecting to OT networks. Exploitation of this vulnerability could sever all remote operator access simultaneously or, worse, give an attacker a foothold on the device that bridges the IT and OT networks. Source: CISA KEV Catalog

🟠 [CRITICAL VULNERABILITY] Microsoft SQL Server — Remote Code Execution Vulnerability (CVE-2019-1068)

On August 26, 2026, CISA added CVE-2019-1068 to the KEV catalog. This is a remote code execution vulnerability in Microsoft SQL Server — confirmed actively exploited. While the CVE dates to 2019, its addition to the KEV now means CISA has evidence of active exploitation in the wild. SQL Server is a foundational component of many SCADA historian platforms, water quality data logging systems, and compliance reporting databases at water utilities. If an attacker gains code execution on a SQL Server instance that houses your process data, the consequences extend beyond data theft: they can manipulate historical records, corrupt compliance data, or use the SQL Server's network position to pivot deeper into OT networks. Source: CISA KEV Catalog

🔴 [REGULATORY MANDATE] AWIA Compliance Countdown — Fewer Than 18 Weeks to December 31, 2026 ERP Deadline

Utilities serving populations of 3,301–49,999 have fewer than 18 weeks remaining until the December 31, 2026 deadline for submitting updated Emergency Response Plans (ERPs) under AWIA. Separately, utilities serving populations of 50,000–99,999 must have updated ERPs completed by June 30, 2026 — that deadline has already passed. If your utility missed it, you are already non-compliant and should contact your EPA regional office immediately. For utilities in the 3,301–49,999 tier that have not yet begun their ERP update, this is a budget and staffing emergency — not just a compliance exercise. Source: WaterISAC (Member Login Required)

Subscribe to The CIP Briefing to read the rest.

Become a premium subscriber to unlock the full Compliance Log, specific vulnerability mitigation steps, and the complete Action Plan.

Upgrade

A subscription gets you: