THE BLUF
This week delivered a significant spike in federal cyber activity that directly impacts water utility IT infrastructure. CISA added ten new Known Exploited Vulnerabilities to the KEV catalog between July 13–16, and several of them hit products that sit squarely in the IT/OT boundary of small and mid-size utilities — Microsoft SharePoint, Microsoft Active Directory Federation Services (ADFS), SonicWall SMA1000 remote access appliances, and a legacy Cisco IOS vulnerability from 2008 that is now confirmed actively exploited. If your utility uses SharePoint for document management (including your AWIA Emergency Response Plans), ADFS for single sign-on to SCADA web portals, SonicWall for VPN access to your plant network, or still runs legacy Cisco routers, you have immediate work to do. Separately, CISA published a new Cybersecurity Advisory (AA26-194A) on Russian state-sponsored targeting of routers — and if your utility's edge routers connect your treatment plant to the internet, this advisory is talking directly to you. On the regulatory front, utilities serving 3,301–49,999 people are now inside six months of the December 31, 2026 ERP deadline. If you haven't started drafting your updated Emergency Response Plan, you are behind. Use the action items below to close your highest-risk gaps this week.
THREAT INTELLIGENCE
🟡 [ACTIVE THREAT INTEL] CISA Advisory AA26-194A — Russian State-Sponsored Actors Targeting Router Infrastructure
On July 13, 2026, CISA published Cybersecurity Advisory AA26-194A: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting. This advisory warns that Russian state-sponsored cyber actors are actively exploiting poorly configured and unpatched edge routers to establish persistent access to victim networks, including critical infrastructure. Routers are the first device an adversary touches when probing your network perimeter. For water utilities that use internet-connected routers to bridge their corporate IT network to their OT/SCADA environment — or to provide remote access to plant systems — this advisory carries direct operational risk. A compromised router gives the adversary a silent foothold to observe traffic, intercept credentials, and pivot toward process control systems without triggering endpoint security tools. Source: CISA Cybersecurity Alerts & Advisories
🟠 [CRITICAL VULNERABILITY] Two New Microsoft SharePoint Deserialization/Auth Bypass Vulnerabilities Added to KEV — Active Exploitation Confirmed
CISA added two new SharePoint vulnerabilities to the KEV catalog this week: CVE-2026-58644 (Deserialization of Untrusted Data, added July 16) and CVE-2026-56164 (Missing Authentication for Critical Function, added July 14). Both are confirmed under active exploitation. CISA also published a separate alert on July 14 titled "CISA Urges SharePoint Hardening After New Exploitations." This is the second consecutive week SharePoint has appeared on the KEV — last week's CVE-2026-45659 remains active as well. Many water utilities use SharePoint to store and share sensitive operational documents including AWIA ERPs, RRAs, standard operating procedures, and chemical inventory records. A compromised SharePoint server can give an attacker access to your entire operational playbook, including the emergency procedures you'd use to respond to the very attack they're conducting. Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] SonicWall SMA1000 Remote Access Appliances — Two Actively Exploited Vulnerabilities
On July 14, CISA added CVE-2026-15409 (Server-Side Request Forgery) and CVE-2026-15410 (Code Injection) affecting SonicWall SMA1000 appliances to the KEV catalog. SonicWall SMA devices are commonly deployed by small and mid-size organizations — including water utilities — as their primary VPN/remote access gateway. These are the exact devices that IT contractors, SCADA integrators, and on-call operators use to remotely connect to plant networks. A compromised SMA appliance hands the adversary the same remote access your operators use, without needing credentials. Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] Microsoft Active Directory Federation Services — Insufficient Access Control
On July 14, CISA added CVE-2026-56155 (Insufficient Granularity of Access Control) affecting Microsoft Active Directory Federation Services (ADFS) to the KEV catalog under active exploitation. ADFS is commonly used to provide single sign-on (SSO) authentication to web-based applications, including SCADA web dashboards, historian portals, and utility management platforms. An exploited ADFS server can allow an attacker to bypass authentication controls and access any federated application — including OT-adjacent systems — without valid credentials. Source: CISA KEV Catalog
🟡 [ACTIVE THREAT INTEL] KNX Building Automation Protocol Vulnerability Added to KEV — OT Relevance for Facilities
On July 15, CISA added CVE-2023-4346 affecting the KNX Association KNX Protocol Connection Authorization Option 1 to the KEV catalog. This is an overly restrictive account lockout mechanism vulnerability. KNX is an OT protocol used in building automation systems (BAS) that manage HVAC, lighting, and access control in facilities — including water treatment plant buildings. If your facility uses KNX-based building automation, this vulnerability could allow an attacker to lock out legitimate administrators. Source: CISA KEV Catalog
🟡 [ACTIVE THREAT INTEL] WaterISAC — Check for Member Alerts and Sector-Specific Threat Feeds
Given the elevated volume of federal advisories this week — particularly the Russian router-targeting advisory and the SharePoint exploitation wave — WaterISAC may have posted member-only threat intelligence, indicators of compromise, or sector-specific operational alerts relevant to your utility. Members should log in and review any postings from the past seven days. Source: WaterISAC (Member Login Required)
🔴 [REGULATORY MANDATE] AWIA Compliance — December 31, 2026 ERP Deadline Now Under Six Months Away
No new EPA enforcement guidance was published in the past seven days. The regulatory posture remains unchanged but the clock is ticking:
Utilities serving 50,000–99,999 people: If you did not certify your updated Emergency Response Plan (ERP) by June 30, 2026, you are currently non-compliant with AWIA Section 2013.
Utilities serving 3,301–49,999 people: If you did not certify your recertified Risk and Resilience Assessment (RRA) by June 30, 2026, you are currently non-compliant. Your updated ERP is legally due December 31, 2026 — that deadline is now fewer than six months away. If you have not begun drafting, you are behind.
EPA certification requires formal submission via the agency's online webform. Source: EPA Cybersecurity for the Water Sector
Subscribe to The CIP Briefing to read the rest.
Become a premium subscriber to unlock the full Compliance Log, specific vulnerability mitigation steps, and the complete Action Plan.
Upgrade