CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

2026-07-30T21:24:02Z20048bed137f830ce388ecb15918915ecabdabb027ec4686a63e7ab81fb37b0f
CVE-2021-27137CVE-2023-4346CVE-2025-68686CVE-2026-0770CVE-2026-16232CVE-2026-16812CVE-2026-20316CVE-2026-25089CVE-2026-39808CVE-2026-46817CVE-2026-50522CVE-2026-58644CVE-2026-60137CVE-2026-63030CISAFortinetKnown Exploited VulnerabilitiesMicrosoft SharePointOT securityPLCRockwell MicroLogixWordPressactive exploitationcritical infrastructureinternet-exposed assetsnetwork appliancesoperational technologyvulnerability managementwater and wastewater systems

What happened

CISA reports active exploitation of multiple vulnerabilities added to its Known Exploited Vulnerabilities catalog and warns that threat actors are targeting internet-exposed programmable logic controllers in the Water and Wastewater Systems sector. Recommended actions include removing direct PLC internet exposure, using VPNs or gateways, changing default passwords, restricting access by IP allowlists, and maintaining clean PLC backups. The breadth of actively exploited vulnerabilities and potential for operational or physical impacts warrants urgent remediation and investigation.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
20048bed137f830ce388ecb15918915ecabdabb027ec4686a63e7ab81fb37b0f
Enrichment time
2026-07-30T21:24:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.