Thursday, August 20, 2026

1 Advisory Published – 8-20-26

Today, CISA’s NCCIC-ICS published one control system security advisory for products from Johnson Controls. 

Advisories  

Johnson Controls Advisory - This advisory describes a cleartext storage of sensitive information in memory vulnerability in the Johnson Controls Simplex Incident Manager fire alarm management system. 


For more information on these advisories, see my article at CFSN Detailed Analysis - - subscription required. 

FCC Sends Satellite Spectrum Abundance Final Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the Federa Communications Commission (FCC) on “Satellite Spectrum Abundance (SB Docket No. 25-180)”. The notice of proposed rulemaking for this action was published on June 27th, 2025.  

According to the 2026 Unified Agenda Entry for this rulemaking: 

“On May 22, 2025, the Commission adopted a Notice of Proposed Rulemaking to seek further comment on ways to use the 12.7-13.25 GHz band (12.7 GHz band) and the 42.0-42.5 GHz band (42 GHz band) more efficiently and intensively. Specifically, the item seeks comment on the possibility of achieving more intensive use of the 12.7 GHz band by satellite communications through the removal of existing regulatory restrictions and the opening of the band to a wider range of satellite operations. Likewise, it seeks comment on the potential for more intensive use of the 42 GHz band by adding for the first time an allocation for fixed-satellite service (FSS). In both instances, the item seeks comment on ways to protect any incumbent spectrum users in the bands, as well as ways to protect spectrum users, particularly Federal operators, in adjacent bands.” 

Wednesday, August 19, 2026

Review - ChemLock Fact Sheets – August 2026

For those of you familiar with my “Looking Back” series of blog posts (latest here), there was almost one today about a post of mine from December 2021 on “Review - ChemLock Fact Sheets”. However, after reviewing the CISA ChemLock web site, I decided that it was probably more appropriate to do a new blog post on the topic. 

Fact Sheets 

Early in the CFATS program, DHS started producing a number of short informational brochures about various chemical security topics. Typically just two pages, these Fact Sheets provided a brief look at a specific topic and provided links to other, more detailed information about the topics. They were never designed to make someone a chemical security expert, but they did form a valuable library for chemical professionals to become more aware of security issues. 

When I wrote that first blog post (CFSN version here) there were just seven fact sheets on the ChemLock web site. Now there are three separate pages listing listing 14 separate ChemLock Fact Sheets: 

Commentary  

The Office of Chemical Security continues to have a problem publicly sharing information on the ChemLock Program. While there have been training announcements from @CISAgov for various ChemLock classes (here is the most recent), I have not seen any other outreach efforts and no mentions of these new fact sheets. I understand that CISA is still recovering from the emasculation of the agency that occurred last year, but if they want to keep the ChemLock program going, they are going to have to start making more of an effort to bring facilities into the fold. Publicly talking about the program is an important part of that effort. 


For more information on these fact sheets, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/chemlock-fact-sheets-august-2026 - subscription required. 

Tuesday, August 18, 2026

CISA Adds VMware Vulnerability to KEV Catalog – 8-18-26

Today, CISA announced that it had added a path traversal vulnerability in the VMware vCenter (multiple VMware products are affected by the vulnerability) product to their Known Exploited Vulnerabilities (KEV) catalog. Broadcom previously disclosed the vulnerability and updated their advisory on August 3rd, 2026; they provide additional information here. The vulnerability was reported to Broadcom by Phil Brass and Matt South of Atredis Partners. Two separate Medium articles have reported public exploitation of the vulnerability:  

CISA has directed federal agencies to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. 

A compliance deadline of August 21st, 2026, has been established. 

Review – 2 Advisories Published – 8-18-26

Today CISA’s NCCIC-ICS published two control system security advisories for products from Siemens and CISA. I also take a down-the-rabbit-hole look at the Github advisories for the CISA Malcom vulnerabilities. 

Advisories  

  • Siemens Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Simcenter Nastran FEM modeling tool. The vulnerability was reported to Siemens by Michael Heinzl. 
  • CISA Advisory - This advisory describes six vulnerabilities in the CISA Malcom network traffic analysis tool. The vulnerabilities were reported to CISA separately by pavanchow, kah-ja, DeathRipper21, and tinb0y. 


For more information on these advisories, as well as a DTRH look at CISA vulnerability reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-8-18-26 - subscription required. 

 
/* Use this with templates/template-twocol.html */