THE BLUF

Two vulnerabilities added to the CISA KEV catalog on August 11 demand your attention this week — and one of them is a Cisco ASA/FTD firewall flaw that could sever the single most important connection between your remote sites and your OT environment. If your utility uses a Cisco Adaptive Security Appliance or Firepower Threat Defense device as its perimeter firewall — and a significant number of small and mid-size water utilities do — CVE-2026-20349 is being actively exploited right now. This is an unauthenticated Denial-of-Service (DoS) vulnerability. An attacker sending a crafted request can force your firewall to crash and reload, instantly dropping all VPN connections, cutting off remote telemetry, and blinding your on-call operators to SCADA alarms. The second KEV, CVE-2026-68820, hits the Windows networking stack itself — a use-after-free in the Ancillary Function Driver for WinSock that could give an attacker who already has a foothold on your network the ability to escalate to SYSTEM-level privileges on any Windows machine, including your HMI workstations. Separately, CISA released a joint advisory on Gunra ransomware (AA26-222A, August 10) — a ransomware variant now actively targeting critical infrastructure organizations. If Gunra hits your utility, remember: under CIRCIA, any ransomware payment must be reported to CISA within 24 hours, and the 72-hour incident reporting clock starts the moment you "reasonably believe" a qualifying cyber incident has occurred. On the compliance calendar: utilities serving 3,301–49,999 people have a December 31, 2026 deadline for updated Emergency Response Plans — now less than 20 weeks away. If you haven't engaged your team on that ERP update, this is the week to start.

THREAT INTELLIGENCE

🟠 [CRITICAL VULNERABILITY] Cisco ASA/FTD Firewall — Denial-of-Service Vulnerability (CVE-2026-20349)

On August 11, 2026, CISA added CVE-2026-20349 to the Known Exploited Vulnerabilities catalog. This vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) — the firewall platforms that serve as the primary perimeter defense and VPN gateway for thousands of water and wastewater utilities. Active exploitation is confirmed. This is a remote, unauthenticated Denial-of-Service (DoS) vulnerability affecting the device's SSL VPN service. By sending a crafted HTTP request, an attacker can force the firewall to unexpectedly crash and reload. While this does not allow for credential theft or data extraction, the operational impact is immediate: a crashed firewall drops all active VPN tunnels, severs remote telemetry to booster stations, and cuts off SCADA alerts to your on-call operators. Adversaries frequently use targeted DoS attacks to intentionally blind operators right before or during a physical or secondary digital attack, making this a critical operational risk. Source: CISA KEV Catalog

🟠 [CRITICAL VULNERABILITY] Microsoft Windows — WinSock Use-After-Free Privilege Escalation (CVE-2026-68820)

On August 11, 2026, CISA added CVE-2026-68820 to the KEV catalog. This vulnerability affects the Windows Ancillary Function Driver for WinSock — a core Windows kernel-mode driver present on every Windows machine in your environment. Active exploitation is confirmed. A use-after-free flaw in this driver allows a local attacker to escalate privileges to SYSTEM level. For water utilities, this is the "second punch" in a two-step attack: an adversary who gains initial access (via phishing, a compromised remote desktop, or a stolen VPN credential from the Cisco flaw above) can use this vulnerability to gain full administrative control over any Windows-based HMI workstation, SCADA server, or historian in your environment. SYSTEM-level access means the attacker can disable security software, install persistence mechanisms, dump additional credentials, and modify or disable process controls. Source: CISA KEV Catalog

🟡 [ACTIVE THREAT INTEL] CISA Advisory AA26-222A: #StopRansomware — Gunra Ransomware

On August 10, 2026, CISA published Cybersecurity Advisory AA26-222A covering Gunra ransomware, a variant actively targeting critical infrastructure organizations. Gunra operators employ double-extortion tactics — encrypting systems while simultaneously exfiltrating data and threatening to publish it. For water utilities, a ransomware event doesn't just mean lost files and a recovery bill — it means potential loss of SCADA visibility, disrupted chemical dosing automation, and manual operations for days or weeks while systems are rebuilt. This advisory is relevant to utilities of all sizes. The operational budget impact of a ransomware event at a small utility can be catastrophic — often exceeding an entire year's IT budget in recovery costs alone. Under CIRCIA, the 72-hour reporting clock begins the moment a covered entity "reasonably believes" a qualifying cyber incident has occurred. Ransomware payments must be reported within 24 hours. Source: CISA Cybersecurity Advisories

🔴 [REGULATORY MANDATE] AWIA Compliance — ERP Deadline for 3,301–49,999 Population Tier

No new regulatory action was published in the past 7 days, but the compliance clock continues. Utilities serving populations of 3,301–49,999 must submit updated Emergency Response Plans (ERPs) by December 31, 2026. Utilities serving 50,000–99,999 must have updated ERPs submitted by June 30, 2026 — that deadline has already passed. If you are in the smaller tier and have not started your ERP update, you are now inside the 20-week window. Your ERP must reflect the findings of your most recent Risk and Resilience Assessment. Treat this week's Cisco and Windows KEVs as a forcing function: if these vulnerabilities exist in your environment, they belong in your RRA and your updated ERP as identified risks.

Subscribe to The CIP Briefing to read the rest.

Become a premium subscriber to unlock the full Compliance Log, specific vulnerability mitigation steps, and the complete Action Plan.

Upgrade

A subscription gets you: