Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
5 days ago

Coordinated "cyberattack" on Minnesota water utilities: What you need to know

A coordinated cyber attack disrupted water and wastewater operations in more than 30 Minnesota communities on July 26-27, 2026; attribution remains pending a federal investigation. Four days prior, CISA and six federal agencies updated Advisory AA26-097A, documenting Iranian-affiliated exploitation of internet-connected PLCs across US water, energy, and government sectors. This FAQ addresses both.

CVE-2021-22681 is listed in CISA's Known Exploited Vulnerabilities catalog in connection with the activity documented in AA26-097A; the advisory does not name it by CVE ID, and it has not been confirmed as the vector for the Minnesota attacks, which remain under active federal investigation. CVE-2023-3595 and CVE-2024-6242 are included as platform hardening references for ControlLogix environments only.

CVEDescriptionCVSSv3
CVE-2021-22681Rockwell Automation Studio 5000 Logix Designer / RSLogix 5000 Authentication Bypass Vulnerability9.8
CVE-2023-3595Rockwell Automation ControlLogix 1756 Communication Module Remote Code Execution Vulnerability9.8
CVE-2024-6242Rockwell Automation ControlLogix 1756 Trusted Slot Bypass Vulnerability8.4

CVE-2021-22681 is confirmed exploited in the AA26-097A campaign and has no available vendor patch. CVE-2023-3595 and CVE-2024-6242 are platform hardening reference for ControlLogix environments only.

For more information, including the availability of patches and Tenable product coverage, please visit our blog.

No RepliesBe the first to reply