THE BLUF
No new water-sector-specific cybersecurity advisories were published by CISA or EPA in the past 7 days. However, do not mistake quiet for safe. CISA added 10 new Known Exploited Vulnerabilities to the KEV catalog between August 31 and September 4, and two sets of them matter to you right now. Two SonicWall SMA1000 appliance vulnerabilities (CVE-2026-83548 and CVE-2026-83549) — a server-side request forgery and an OS command injection — are confirmed actively exploited. If your utility uses a SonicWall SMA appliance for remote access (and many small utilities do), an attacker can chain these flaws to pivot from your VPN gateway directly into your OT network. That means your SCADA integrator's remote tunnel could become the attacker's front door. Separately, a Google Chrome V8 type confusion vulnerability (CVE-2026-85046) was added on September 4 — every HMI workstation and operator laptop running Chrome is a target. Meanwhile, on the compliance clock: utilities serving 3,301–49,999 people now have fewer than 17 weeks until the December 31, 2026 deadline for updated Emergency Response Plans under AWIA. If you haven't started that ERP update yet, you are behind. And utilities serving 50,000–99,999 people have their updated ERPs due June 30, 2026 — that deadline has already passed. Confirm your certifications are filed.
THREAT INTELLIGENCE
🟠 [CRITICAL VULNERABILITY] SonicWall SMA1000 Appliances — Dual Active Exploitation (CVE-2026-83548 & CVE-2026-83549)
On September 2, 2026, CISA added two SonicWall SMA1000 vulnerabilities to the KEV catalog. CVE-2026-83548 is a server-side request forgery (SSRF) flaw, and CVE-2026-83549 is an OS command injection vulnerability. Both are confirmed actively exploited. SonicWall SMA (Secure Mobile Access) appliances are widely deployed by small and mid-size organizations — including water utilities — as VPN concentrators and remote access gateways. These are the exact devices that bridge an operator's laptop at home to the SCADA network at the plant. The SSRF flaw allows an attacker to force the appliance to make unauthorized internal requests, potentially mapping your internal network. The command injection flaw allows arbitrary command execution on the appliance itself. Chained together, these give an attacker the ability to compromise the remote access device and use it as a launchpad into the OT environment. For utilities where the SonicWall appliance is the only perimeter device between the internet and the control network, exploitation of these vulnerabilities is functionally equivalent to handing an attacker the keys to the plant. Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] Google Chromium V8 — Type Confusion Vulnerability (CVE-2026-85046)
On September 4, 2026, CISA added CVE-2026-85046 to the KEV catalog. This is a type confusion vulnerability in Google Chrome's V8 JavaScript engine, confirmed actively exploited in the wild. At water utilities, Chrome is often the default browser on HMI workstations, SCADA operator laptops, historian servers, and even the front desk PC that's on the same flat network as everything else. A type confusion flaw in V8 means a specially crafted web page — delivered via phishing, a watering-hole attack, or even a compromised vendor portal — can achieve code execution on any machine running an unpatched Chrome browser. If that machine has line-of-sight to OT assets, the attacker inherits that access. Source: CISA KEV Catalog
🔴 [REGULATORY MANDATE] AWIA Compliance Clock — ERP Deadline Now Under 17 Weeks
No new EPA guidance was published in the past 7 days, but the calendar does not pause. Utilities serving 3,301–49,999 people must submit updated Emergency Response Plans (ERPs) by December 31, 2026. That is now fewer than 17 weeks away. Utilities serving this population tier should have already completed recertified Risk and Resilience Assessments (RRAs) by the June 30, 2026 deadline. If that was missed, the ERP cannot be properly built on top of it. Separately, utilities serving 50,000–99,999 people had their updated ERP deadline of June 30, 2026 — verify with your state primacy agency that your certifications are on file. Source: WaterISAC (Member Login Required)
ACCESS RESTRICTED: UNLOCK THE ACTION PLAN
You have the threat data. Now get the mitigation plan. Upgrade to Premium to unlock the step-by-step remediation checklist for these vulnerabilities, plus audit-ready compliance logs and 5-minute tabletop scenarios.
Upgrade