THE BLUF
If your utility runs a WordPress-based public website — and most small water systems do — you have a serious problem this week. CISA added two WordPress Core vulnerabilities to the KEV catalog on July 21, including a SQL injection flaw (CVE-2026-60137) that is confirmed under active exploitation. This is not a plugin issue; this is the WordPress engine itself. If your public-facing website shares any infrastructure with your business network — same server, same credentials, same subnet — an attacker who compromises your website has a stepping stone toward your operational systems. Separately, CISA added a third Microsoft SharePoint vulnerability (CVE-2026-50522) to the KEV on July 22, making it three SharePoint CVEs in two weeks. If your IT contractor hasn't patched SharePoint yet, you are now three CVEs behind. CISA also published Cybersecurity Advisory AA26-204A on July 23 warning of a Russian state-supported phishing campaign targeting Zimbra Collaboration Suite — a product some smaller utilities use for email. On the regulatory clock: utilities serving 3,301–49,999 people now have five months until their recertified Risk and Resilience Assessments are legally due on June 30, 2026 — that deadline has passed. If you missed it, contact your EPA region immediately. Your updated Emergency Response Plans are due December 31, 2026 — just over five months out. Every week you wait narrows your runway and increases the cost of a rush engagement with a consultant. Act now while the work is manageable.
THREAT INTELLIGENCE
🟡 [ACTIVE THREAT INTEL] CISA Advisory AA26-204A — Russian State-Supported Phishing Campaign Targeting Zimbra Collaboration Suite
On July 23, 2026, CISA published Cybersecurity Advisory AA26-204A, warning that Russian state-supported cyber actors are conducting a targeted phishing campaign against users of Zimbra Collaboration Suite, an email and calendar platform used by organizations that cannot afford or choose not to use Microsoft 365 or Google Workspace. Several small water utilities and municipal governments run Zimbra as their primary email system. The advisory describes phishing emails crafted to steal Zimbra credentials, which then give the attacker full access to the victim's email account — including password reset flows, internal communications about plant operations, vendor contacts, and any AWIA-related documents shared via email. A compromised email account is also the classic launchpad for business email compromise (BEC) fraud targeting accounts payable, which for a small utility could mean a diverted chemical supply payment or a fraudulent wire transfer. Source: CISA Cybersecurity Alerts & Advisories
🟠 [CRITICAL VULNERABILITY] Third Microsoft SharePoint Deserialization Vulnerability in Two Weeks — CVE-2026-50522 Added to KEV
On July 22, CISA added CVE-2026-50522 (Deserialization of Untrusted Data) affecting Microsoft SharePoint to the KEV catalog. This is the third SharePoint CVE added to the KEV in the past two weeks, following CVE-2026-58644 and CVE-2026-56164 from last week. Active exploitation is confirmed. The sustained targeting of SharePoint tells a clear story: adversaries have identified SharePoint as a high-value target across critical infrastructure, and they are burning through multiple exploit chains to maintain access. For water utilities storing AWIA Emergency Response Plans, chemical inventories, standard operating procedures, or engineering drawings on SharePoint, this is an ongoing and escalating risk to your most sensitive operational documents. Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] WordPress Core — Two Actively Exploited Vulnerabilities (SQL Injection and Interpretation Conflict)
On July 21, CISA added two WordPress Core vulnerabilities to the KEV catalog: CVE-2026-60137 (SQL Injection) and CVE-2026-63030 (Interpretation Conflict). These are not third-party plugin issues — they affect the WordPress Core software itself. The vast majority of small water utility public websites, customer portals, and even some internal document sites run on WordPress. A SQL injection in the core platform means an attacker can potentially extract database contents — usernames, passwords, customer records, and any content stored in the WordPress database — without authenticating. If your WordPress installation shares a database server or network segment with business IT systems, or if administrators reuse credentials between the website and internal systems (including SCADA web interfaces), this vulnerability creates a direct path from a public-facing website to your operational environment. Source: CISA KEV Catalog
Subscribe to The CIP Briefing to read the rest.
Become a premium subscriber to unlock the full Compliance Log, specific vulnerability mitigation steps, and the complete Action Plan.
Upgrade