CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
2026-07-30T21:24:02Z•20048bed137f830ce388ecb15918915ecabdabb027ec4686a63e7ab81fb37b0f
CVE-2021-27137CVE-2023-4346CVE-2025-68686CVE-2026-0770CVE-2026-16232CVE-2026-16812CVE-2026-20316CVE-2026-25089CVE-2026-39808CVE-2026-46817CVE-2026-50522CVE-2026-58644CVE-2026-60137CVE-2026-63030CISAFortinetKnown Exploited VulnerabilitiesMicrosoft SharePointOT securityPLCRockwell MicroLogixWordPressactive exploitationcritical infrastructureinternet-exposed assetsnetwork appliancesoperational technologyvulnerability managementwater and wastewater systems
What happened
CISA reports active exploitation of multiple vulnerabilities added to its Known Exploited Vulnerabilities catalog and warns that threat actors are targeting internet-exposed programmable logic controllers in the Water and Wastewater Systems sector. Recommended actions include removing direct PLC internet exposure, using VPNs or gateways, changing default passwords, restricting access by IP allowlists, and maintaining clean PLC backups. The breadth of actively exploited vulnerabilities and potential for operational or physical impacts warrants urgent remediation and investigation.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 20048bed137f830ce388ecb15918915ecabdabb027ec4686a63e7ab81fb37b0f
- Enrichment time
- 2026-07-30T21:24:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.