THE BLUF
This was a quiet week for water-sector-specific federal advisories — no new CISA alerts or advisories naming the Water and Wastewater Systems Sector were published in the past 7 days. That silence is not permission to stand down. The July 30 CISA Alert calling out PLC targeting in water utilities remains the most recent sector-specific directive, and the threat actors it describes have not gone away. What did drop this week are six new additions to the CISA Known Exploited Vulnerabilities (KEV) catalog between August 3–7. Two of them — Progress LoadMaster and Apache Tomcat — are directly relevant to small and mid-size water utilities. If your IT contractor uses a Progress LoadMaster load balancer to manage traffic to your SCADA web interfaces or remote access portals, a command injection vulnerability (CVE-2026-8037) is now being actively exploited in the wild. Apache Tomcat (CVE-2026-34486) is even more common — it's the backbone of many web-based OT dashboards, historian front-ends, and SCADA web applications deployed at water utilities. A missing encryption flaw means sensitive data — potentially including credentials — could be intercepted in transit. Both require action from your IT contractor this week. On the regulatory clock: utilities serving 3,301–49,999 people have a hard December 31, 2026 deadline for updated Emergency Response Plans — now less than five months away. If you haven't started that ERP update, the clock is working against you.
THREAT INTELLIGENCE
🟠 [CRITICAL VULNERABILITY] Progress LoadMaster — Command Injection (CVE-2026-8037)
On August 7, 2026, CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog. This vulnerability affects Progress LoadMaster, a load balancing appliance used to distribute network traffic across servers and applications. Active exploitation is confirmed. In water utility environments, LoadMaster appliances may sit in front of web-based SCADA portals, remote access gateways, or historian servers — managing which traffic reaches internal systems. A command injection flaw allows an attacker to execute arbitrary operating system commands on the appliance itself. Once an attacker owns your load balancer, they can redirect traffic, intercept credentials, inject malicious content into sessions, or pivot directly into the OT network behind it. This is a perimeter device with deep visibility into your traffic — it's a high-value target. Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] Apache Tomcat — Missing Encryption of Sensitive Data (CVE-2026-34486)
On August 4, 2026, CISA added CVE-2026-34486 to the KEV catalog. Apache Tomcat is an open-source web server and Java servlet container that is widely deployed across the water sector — often without operators even knowing it. It is the engine behind many web-based HMI dashboards, SCADA historian web portals, alarm notification systems, and vendor-provided OT management interfaces. This vulnerability involves missing encryption of sensitive data, meaning information passing through Tomcat — including login credentials, session tokens, and potentially process data — may be transmitted in cleartext or with inadequate protection, exposing it to interception. Active exploitation is confirmed. For a utility where Tomcat serves the front-end to your SCADA system, this means an attacker on the same network segment (or one who has compromised an adjacent device) could capture operator credentials and gain direct access to your control environment. Source: CISA KEV Catalog
🔴 [REGULATORY MANDATE] AWIA Compliance — ERP Deadline Approaching for 3,301–49,999 Population Tier
No new regulatory action was published in the past 7 days, but the compliance clock continues to tick. Utilities serving 3,301–49,999 people have recertified Risk and Resilience Assessments that were due June 30, 2026. If your utility missed that deadline and has not yet contacted your EPA regional office, do so immediately. Your updated Emergency Response Plans (ERPs) are legally due December 31, 2026 — now under five months away. Utilities serving 50,000–99,999 people also face an updated ERP deadline of June 30, 2026, which has already passed. Source: EPA Cybersecurity for the Water Sector
Subscribe to The CIP Briefing to read the rest.
Become a premium subscriber to unlock the full Compliance Log, specific vulnerability mitigation steps, and the complete Action Plan.
Upgrade