THE BLUF
This was a high-tempo week from CISA — nine new CVEs added to the Known Exploited Vulnerabilities catalog between August 17 and August 21 — and the one that should keep water utility managers up at night is CVE-2026-33824, a double-free vulnerability in the Microsoft Internet Key Exchange (IKE) Service Extensions. If your utility runs site-to-site VPN tunnels between treatment plants, pump stations, and your main operations center using Windows-based IKE/IPsec — and many small utilities do — this flaw could let an attacker crash or compromise the VPN service that holds your OT communications together. Losing that tunnel doesn't just mean "IT is down." It means your remote SCADA polling stops, your operators lose visibility into remote sites, and you're running blind until someone drives out to verify process conditions in person. Separately, on the advisory front: CISA published Cybersecurity Advisory AA26-231A on August 19, "Defending Against an Active Threat to Siemens S7 Series PLCs." While the Siemens S7 threat was introduced in our prior briefing, the formal advisory release this week elevates the urgency — this is now a fully documented, multi-agency advisory with specific TTPs and IOCs, not just a KEV entry. On the compliance calendar: utilities serving 3,301–49,999 people now have fewer than 19 weeks until the December 31, 2026 deadline for updated Emergency Response Plans under AWIA. If your ERP update hasn't started, you are behind.
THREAT INTELLIGENCE
🟡 [ACTIVE THREAT INTEL] CISA Publishes Formal Advisory AA26-231A — Defending Against an Active Threat to Siemens S7 Series PLCs
On August 19, 2026, CISA released Cybersecurity Advisory AA26-231A, titled "Defending Against an Active Threat to Siemens S7 Series PLCs." While the threat to Siemens S7 PLCs was flagged in prior weeks, the publication of a formal, numbered advisory represents a significant escalation — this document now contains specific threat actor tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and detailed mitigation guidance developed with multi-agency partners. For water and wastewater utilities, Siemens S7-series PLCs are among the most commonly deployed controllers for process automation — managing everything from chemical feed pumps and blower systems to valve sequencing and filter backwash. A formal advisory of this type means the federal government has high-confidence intelligence that these specific controllers are being actively targeted. This is not a theoretical exercise. Source: CISA Cybersecurity Advisories
🟠 [CRITICAL VULNERABILITY] Microsoft Internet Key Exchange (IKE) Service Extensions — Double Free Vulnerability (CVE-2026-33824)
On August 18, 2026, CISA added CVE-2026-33824 to the KEV catalog. This vulnerability affects the Microsoft Internet Key Exchange (IKE) Service Extensions — the Windows component that negotiates IPsec VPN tunnels. Active exploitation is confirmed. A double-free memory corruption flaw in the IKE service can allow a remote attacker to execute arbitrary code or cause a denial-of-service condition on the affected Windows system. For water utilities, the IKE service is the backbone of site-to-site VPN connectivity between geographically distributed facilities. If an attacker exploits this vulnerability on the Windows server or workstation handling your VPN negotiations, the immediate result could be the collapse of your encrypted tunnel to remote pump stations, lift stations, or water towers — severing SCADA polling and telemetry in a single stroke. The secondary risk is code execution, which could give the attacker a persistent foothold on a system that by design has network connectivity to every remote OT site. Source: CISA KEV Catalog
🟠 [CRITICAL VULNERABILITY] Microsoft SharePoint — Weak Authentication Vulnerability (CVE-2026-55040)
On August 18, 2026, CISA added CVE-2026-55040 to the KEV catalog. This vulnerability affects Microsoft SharePoint — a platform many utilities use to store operational documents, SOPs, emergency contact lists, and even SCADA configuration files. Active exploitation is confirmed. A weak authentication flaw allows an attacker to bypass security controls and gain unauthorized access to SharePoint resources. For utilities that store sensitive OT documentation — network diagrams, PLC configuration backups, chemical inventory records, or AWIA-required Risk and Resilience Assessments — on SharePoint, this vulnerability represents a direct pathway to intelligence gathering that supports follow-on attacks against your physical infrastructure. Source: CISA KEV Catalog
🔴 [REGULATORY MANDATE] AWIA Compliance Countdown — ERP Deadline Now Under 19 Weeks
Utilities serving 3,301–49,999 people face a legal deadline of December 31, 2026 for submission of updated Emergency Response Plans (ERPs). That deadline is now fewer than 19 weeks away. Additionally, utilities serving 50,000–99,999 people had recertified Risk and Resilience Assessments (RRAs) legally due June 30, 2026 — if your utility missed that deadline, corrective action should be underway immediately. Under CIRCIA, remember: the 72-hour incident reporting clock starts the moment a covered entity "reasonably believes" a qualifying cyber incident has occurred, and any ransomware payment must be reported to CISA within 24 hours.
Subscribe to The CIP Briefing to read the rest.
Become a premium subscriber to unlock the full Compliance Log, specific vulnerability mitigation steps, and the complete Action Plan.
Upgrade