Wednesday, September 23, 2026

Review – Bills Introduced – 9-22-26

Yesterday, with just the Senate in session, there were 18 bills introduced. One of those bills may receive additional coverage in this blog: 

S 5450 A bill to adjust the rail safety inspections General Schedule classification, and for other purposes. Peters, Gary C. [Sen.-D-MI] 


For more information on this bill, including legislative history for similar bills in the 118th Congress, as well as a mention in passing of a spending reduction resolution, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-9-22-26 - subscription required. 

Tuesday, September 22, 2026

Review – Advisories Published – 9-22-26

Today CISA’s NCCIC-ICS published nine control system security advisories for products from OpenPLC, Siemens (6), and Lightweight IP (2).  

Advisories  

OpenPLC Advisory - This advisory describes a cross-site scripting vulnerability in the Autonomy Logic OpenPLC. The vulnerability was reported to CISA by Rajivarnan R. and Shirshak of Secnora. 

Siemens Advisory #1 - This advisory describes an improper validation of specified type of input vulnerability in the Siemens WTV676 and WTV776 products. The vulnerability was self-reported. 

Siemens Advisory #2 - This advisory describes a relative path traversal vulnerability in the Siemens SIMOVE Fleetmanager and SIPLANT products. The vulnerability was self-reported. 

Siemens Advisory #3 - This advisory discusses a weak password recovery mechanism for forgotten password vulnerability in the Siemens Industrial Edge Management product line. This is a third-party (Red Hat) vulnerability. 

Siemens Advisory #4 - This advisory describes a code injection vulnerability in the Siemens Desigo CC family. The vulnerability was reported by Michelin CERT. 

Siemens Advisory #5 - This advisory discusses the Copy Fail vulnerability in the Siemens SIPLUS and SIMATIC products. This is a third-party (Linux) vulnerability.  

Siemens Advisory #6 - This advisory describes an unrestricted upload of file with dangerous type vulnerability in the Siemens Siveillance Control product. The vulnerability was self-reported. 

Lightweight IP (lwIP) Advisory #1 - This advisory describes a double free vulnerability in the Lightweight IP. The vulnerability was reported to CISA by Eric Evenchick of Tetrel Security. 

Lightweight IP (lwIP) Advisory #2 - This advisory describes an out-of-bounds write vulnerability in the lwIP TCP/IP Stack MQTT Client Application. The vulnerability was reported to CISA by Shahriyar Jalayeri of ByteRay Ltd. 


For more information on these advisories, as well as a DTRH look at the Copy Fail vulnerability in products from Siemens, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/advisories-published-9-22-26 - subscription required. 

Short Takes – 9-22-26 - Federal Register Edition

HSAR – PPE  

Homeland Security Acquisition Regulation, Make Personal Protective Equipment in America Act Restrictions on Foreign Acquisition (HSAR Case 2024-003). DHS final rule. Summary: “DHS is issuing a final rule to amend the Homeland Security Acquisition Regulation (HSAR) codifying how DHS complies with the requirements of the Make Personal Protective Equipment (PPE) in America Act. These changes are intended to ensure the sustainment and expansion of domestic manufacturing for certain types of PPE critical to the United States' national response to a public health crisis. 

Pipeline Safety  

Pipeline Safety: Meeting of the Liquid Pipeline Advisory Committee. PHMSA advisory committee meeting notice. Summary: “This notice announces a public meeting of the Technical Hazardous Liquid Pipeline Safety Standards Committee, also known as the Liquid Pipeline Advisory Committee (LPAC). The meeting will be held virtually to discuss the following notices of proposed rulemaking (NPRMs): “Breakout Tank Inspection,” “Remote Monitoring of Hazardous Liquid Pipeline Rectifiers,” and “Hazardous Liquid Valve Maintenance Schedule.” 

Executive Orders  

EO 14428 - Providing Meaningful Water Quality Improvements Through Collaboration and Oversight of Federal Support. 

EO 14429 - Reinvigorating America's Hunting Heritage. 

EO 14430 - Restoring American Saltwater Angling and Recreation. 

Review – Bills Introduced – 9-21-26

Yesterday, with the House meeting (once again) in pro forma session, there were 27 bills introduced. One of those bills will probably receive additional coverage in this blog: 

HR 10519 To direct the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency, to establish a Critical Infrastructure AI Cyber Defense Pilot Program, and for other purposes. Gottheimer, Josh [Rep.-D-NJ-5]    


For more information on these bills, including legislative history for similar bills in the 118th Congress, as well as a mention in passing of a bill that would direct the EPA to research tropospheric ozone, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-9-21-26 - subscription required. 

Monday, September 21, 2026

CISA Adds Zyxel Vulnerability to KEV – Catalog – 9-21-26 

Today, CISA announced that they had added a stack-based buffer overflow vulnerability in the Zyxel GS1900 series switches to their Known Exploitable Vulnerabilities (KEV) catalog. Zyxel reported the vulnerability on June 16th, 2026. The vulnerability was reported to Zyxel by Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from Institute of Software, Chinese Academy of Sciences (ISCAS). 

Today, GreyNoise reported (in an article about a WordPress exploit): 

“In addition to the above findings, GreyNoise discovered the MCA [malicious cyber actor] targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273. As of 17 September 2026, this is the first publicly documented case of exploitation in the wild of this vulnerability, which is also not on [obviously dated before today’s CISA announcement] the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog at the time of publication. The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries.” 

CISA has directed federal agencies using the affected Zyxel devices to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [Links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

A compliance date of September 24th, 2026, has been established. 

 
/* Use this with templates/template-twocol.html */