cisa
1 TopicCoordinated "cyberattack" on Minnesota water utilities: What you need to know
A coordinated cyber attack disrupted water and wastewater operations in more than 30 Minnesota communities on July 26-27, 2026; attribution remains pending a federal investigation. Four days prior, CISA and six federal agencies updated Advisory AA26-097A, documenting Iranian-affiliated exploitation of internet-connected PLCs across US water, energy, and government sectors. This FAQ addresses both. CVE-2021-22681 is listed in CISA's Known Exploited Vulnerabilities catalog in connection with the activity documented in AA26-097A; the advisory does not name it by CVE ID, and it has not been confirmed as the vector for the Minnesota attacks, which remain under active federal investigation. CVE-2023-3595 and CVE-2024-6242 are included as platform hardening references for ControlLogix environments only. CVE Description CVSSv3 CVE-2021-22681 Rockwell Automation Studio 5000 Logix Designer / RSLogix 5000 Authentication Bypass Vulnerability 9.8 CVE-2023-3595 Rockwell Automation ControlLogix 1756 Communication Module Remote Code Execution Vulnerability 9.8 CVE-2024-6242 Rockwell Automation ControlLogix 1756 Trusted Slot Bypass Vulnerability 8.4 CVE-2021-22681 is confirmed exploited in the AA26-097A campaign and has no available vendor patch. CVE-2023-3595 and CVE-2024-6242 are platform hardening reference for ControlLogix environments only. For more information, including the availability of patches and Tenable product coverage, please visit our blog.27Views0likes0Comments