Tuesday, August 18, 2026

CISA Adds VMware Vulnerability to KEV Catalog – 8-18-26

Today, CISA announced that it had added a path traversal vulnerability in the VMware vCenter (multiple VMware products are affected by the vulnerability) product to their Known Exploited Vulnerabilities (KEV) catalog. Broadcom previously disclosed the vulnerability and updated their advisory on August 3rd, 2026; they provide additional information here. The vulnerability was reported to Broadcom by Phil Brass and Matt South of Atredis Partners. Two separate Medium articles have reported public exploitation of the vulnerability:  

CISA has directed federal agencies to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. 

A compliance deadline of August 21st, 2026, has been established. 

Review – 2 Advisories Published – 8-18-26

Today CISA’s NCCIC-ICS published two control system security advisories for products from Siemens and CISA. I also take a down-the-rabbit-hole look at the Github advisories for the CISA Malcom vulnerabilities. 

Advisories  

  • Siemens Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Simcenter Nastran FEM modeling tool. The vulnerability was reported to Siemens by Michael Heinzl. 
  • CISA Advisory - This advisory describes six vulnerabilities in the CISA Malcom network traffic analysis tool. The vulnerabilities were reported to CISA separately by pavanchow, kah-ja, DeathRipper21, and tinb0y. 


For more information on these advisories, as well as a DTRH look at CISA vulnerability reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-8-18-26 - subscription required. 

Review - S 4565 Introduced – Chinese Cyber Threats

Back in May, Sen Scott (R,FL) introduced S 4565, the Strengthening Cyber Resilience Against State-Sponsored Threats Act. The bill would require CISA to establish an interagency task force to “detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China”. The task force would submit annual classified reports to Congress. No new funding is authorized by this legislation. 

A nearly identical bill, HR 2659, the Strengthening Cyber Resilience Against State-Sponsored Threats Act, was introduced by Rep Ogles (R,TN) in April 2025. On April 9th, 2025, the House Homeland Security Committee held a business meeting where HR 2659 was considered; the bill was ordered reported favorably by a voice vote. The Committee Report was published on August 15th, 2025. On November 17th, the full House took up the bill under the suspension of the rules process; the bill passed by a vote of 402 to 8. No action has been taken on the bill in the Senate. 

A press release from Scott’s office notes that:  

“Senator Rick Scott said, “As the world’s leading digital economy, America has the most to lose in a cyberattack. If we don’t secure our digital infrastructure, hackers could cut power to your house, empty your bank account, or disable life support for a loved one in the hospital. Americans shouldn’t worry about a cyber threat from the CCP, which is why I’m proud to be introducing this legislation with Rep. Ogles. The House has done its job in passing this bill, now we need the Senate to do ours.”” 

Moving Forward  

Both Scott and his sole cosponsor, Sen Fetterman (D,PA), are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there may be adequate influence to see the bill considered by the Committee. I do not see anything in the bill that would engender any organized opposition, though there is a real possibility that the Chair, Sen Paul (R,TN), might have some objections to the bill. I do expect that there would be some level of bipartisan support for this bill. The bill, however, is not politically important enough to take up the limited amount of time left in the session that needs to be expended to be considered under regular order. 


For more information on the provisions of this bill, including a commentary on the lack of participation by the intelligence community, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4565-introduced-chinese-cyber-threats - subscription required. 

Short Takes – 8-18-26 - Federal Register Edition

Advisory Committees  

Secretary of Energy Advisory Board. DOE notice of renewal. Summary: “Pursuant to the Federal Advisory Committee Act and following consultation with the Committee Management Secretariat, General Services Administration, notice is hereby given that the Secretary of Energy Advisory Board (SEAB) will be renewed for a two-year period beginning on August 26, 2026. The Committee provides advice and recommendations to the Secretary of Energy on energy policies; the Department's basic and applied research and developmental activities; economic and national security policy; and on any other activities and operations of the Department of Energy. 

Nominations to the Federal Insecticide, Fungicide, and Rodenticide Act Scientific Advisory Panel (FIFRA SAP). EPA notice. Summary: “The Environmental Protection Agency (EPA or the Agency) is now accepting public comments on the experts the Agency is considering for membership on the Federal Insecticide, Fungicide, and Rodenticide Act (FIFRA) Scientific Advisory Panel (SAP). This document identifies the individuals nominated. The Agency anticipates selecting from those nominees that are identified as interested and available to appoint two new SAP members by October 2026 due to expiring membership terms. Public comments on these nominations will be used to assist the Agency in selecting the new members for the FIFRA SAP. 

Energy Infrastructure  

America's Great Corridors of Commerce; Request for Information. DOT request for information. Summary: “The U.S. Department of Transportation (DOT or the Department), through the Build America Bureau, created the America's Great Corridors of Commerce (AGCC) initiative to unleash opportunities for both highway and rail ROW owners to generate revenue streams through utility colocation that can fund transportation improvement projects, while simultaneously delivering significant economic development to these areas. AGCC is a voluntary, applicant-driven process in which ROW owners propose corridors for strategic colocation of utility infrastructure in the transportation ROW through an innovative public-private partnership (P3) model. Selected corridors receive concierge technical assistance and enhanced collaboration from a team of experts from relevant Federal agencies. In this RFI, DOT seeks comments from the public and interested parties on the AGCC model and the proposed elements of DOT's anticipated AGCC designation process. 

Space Geek  

Notice of Public Comment Period and Request for Comment on the Draft Environmental Assessment for Reditus Space ENOS Reentries in the Gulf of America. FAA notice of availability and public comment. Summary: “In accordance with the National Environmental Policy Act of 1969, as amended (NEPA) and FAA Order 1050.1G, FAA National Environmental Policy Act Implementing Procedures, the FAA is announcing the availability of and requesting comment on the Draft Environmental Assessment for Reditus Space ENOS Reentries in the Gulf of America (Draft EA). 

 
/* Use this with templates/template-twocol.html */