THE BLUF

CISA issued a new Alert on July 30 — published just three days ago — explicitly calling out the Water and Wastewater Systems Sector by name, urging utilities to protect OT systems against activity targeting Programmable Logic Controllers (PLCs). This is not a generic cross-sector advisory. CISA pointed directly at water utilities, which means federal eyes are on this sector right now. If your PLCs are reachable from your business network, or if you have any remote access paths into your OT environment that you haven't hardened, this alert is aimed squarely at you. Separately, CISA added a Cisco Secure Firewall Management Center vulnerability (CVE-2026-20316) to the KEV catalog on July 29 — a hard-coded password flaw. If your utility or your IT contractor uses Cisco firewall appliances managed through FMC, an attacker with knowledge of this hard-coded credential can bypass authentication entirely. That's your perimeter defense — compromised by a password the vendor baked into the product. On the Fortinet side, CVE-2025-68686 was added to the KEV on July 27 — an information exposure flaw in FortiOS. Many small water utilities run Fortinet firewalls as their only line of defense between the internet and their SCADA network. Both of these firewall KEVs need immediate attention from your IT contractor this week. On the regulatory clock: utilities serving 3,301–49,999 people — your recertified Risk and Resilience Assessments were due June 30, 2026. If you missed that deadline, contact your EPA region immediately. Your updated Emergency Response Plans are due December 31, 2026 — exactly five months out.

THREAT INTELLIGENCE

🟡 [ACTIVE THREAT INTEL] CISA Alert — "CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs"

On July 30, 2026, CISA published a new Alert specifically naming the Water and Wastewater Systems Sector, urging operators to protect their OT environments against ongoing activity targeting Programmable Logic Controllers (PLCs). This is a sector-specific call to action — not a general advisory. The alert reinforces the pattern CISA has been tracking throughout 2026: threat actors — including Iranian-affiliated cyber actors documented in Advisory AA26-097A from April — are exploiting PLCs that are internet-exposed, running with default credentials, or accessible through poorly segmented networks. The alert arrives in the context of the broader CISA campaign that began with the December 2024 joint fact sheet on internet-exposed HMIs and the September 2024 alert on unsophisticated OT exploitation. The message from CISA is consistent and escalating: if your PLCs are reachable from outside your plant network, you are a target. Source: CISA Cybersecurity Alerts & Advisories

🟠 [CRITICAL VULNERABILITY] Cisco Secure Firewall Management Center — Hard-Coded Password (CVE-2026-20316)

On July 29, 2026, CISA added CVE-2026-20316 to the KEV catalog. This vulnerability affects Cisco Secure Firewall Management Center (FMC) — the centralized management console used to configure and monitor Cisco firewall appliances. The flaw is a hard-coded password embedded in the product. Active exploitation is confirmed. For water utilities that use Cisco firewalls — especially those managed by a third-party IT contractor — this means an attacker who discovers or obtains the hard-coded credential can authenticate to FMC without needing to steal or crack any user password. From FMC, an attacker can modify firewall rules, open access paths into your OT network, disable logging, or create persistent backdoor access. This vulnerability strikes at the exact device your network depends on for perimeter security. Source: CISA KEV Catalog

🟠 [CRITICAL VULNERABILITY] Fortinet FortiOS — Sensitive Information Exposure (CVE-2025-68686)

On July 27, 2026, CISA added CVE-2025-68686 to the KEV catalog, affecting Fortinet FortiOS. This is an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Active exploitation is confirmed. FortiOS is the operating system that runs on all FortiGate firewall appliances — one of the most commonly deployed firewalls in small and mid-size water utilities. An information exposure flaw can allow an attacker to extract configuration data, credentials, session tokens, or internal network architecture details without authentication. This is typically the first step in a multi-stage attack: the attacker gathers intelligence from your firewall, then uses that information to pivot deeper into your network. Source: CISA KEV Catalog

Subscribe to The CIP Briefing to read the rest.

Become a premium subscriber to unlock the full Compliance Log, specific vulnerability mitigation steps, and the complete Action Plan.

Upgrade

A subscription gets you:

Keep Reading