Wednesday, September 2, 2026

HR 6500 Passed in House – FY 2027 CR

Yesterday, the House took up the Senate Amendment to HR 6500, the Continuing Appropriations and Extensions Act, 2027 under the suspension of the rules process. After about 25 minutes of debate, the House agreed to the Senate amendment by a bipartisan vote of 370 to 48 (29 Republican and 19 Democrats voting NAY).

The amended bill provides a continuation of current federal government spending through December 11th, 2026. 

This is not a ‘clean’ continuing resolution; a number of spending extensions and increases are included in the provisions of this bill. None of those spending actions are of specific interest here except the following Space Geek items of interest: 

  • Section 121 - funding needed to maintain the planned launch schedules for the Geostationary Extended Observations (GeoXO) satellite system. 

The bill also extends the termination date of the following programs (among others) that are tied to the end of the fiscal year: 

  • Section 2011. Cybersecurity Information Sharing Act of 2015, and 
  • Section 2012. Federal Cybersecurity Enhancement Act of 2015.

Tuesday, September 1, 2026

Review – 6 Advisories and 2 Updates Published – 9-1-26

Today CISA’s NCCIC-ICS published six control system security advisories for products from Rockwell Automation. They also updated two advisories for products from Rockwell and Mitsubishi. 

Advisories  

Rockwell Advisory #1 - This advisory describes two vulnerabilities in the Rockwell Historian ME. The vulnerabilities were self-reported. 

Rockwell Advisory #2 - This advisory discusses an infinite loop vulnerability in the Rockwell ControlLogix, CompactLogix, and GuardLogix product lines. This is a third-party vulnerability. 

Rockwell Advisory #3 - This advisory describes an improper restriction of excessive authentication attempts vulnerability in the Rockwell FactoryTalk Activation Manager. The vulnerability was reported to Rockwell by an anonymous researcher. 

Rockwell Advisory #4 - This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Rockwell Logix Platform. The vulnerability was self-reported. 

Rockwell Advisory #5 - This advisory describes two incorrect default conditions vulnerabilities in the Rockwell Redundancy Module Configuration Tool. The vulnerability was self-reported. 

Rockwell Advisory #6 - This advisory describes four vulnerabilities in the Rockwell RSLinx Classic. The vulnerabilities were self-reported. 

Updates 

Rockwell Update - This update provides additional information on the 1734 POINT I/O advisory that was originally published on July 21st, 2026. The new information includes updating impact statement and CVSS scores. 

Mitsubishi Update - This update provides additional information on the Multiple FA Engineering Software Products advisory that was originally published on May 14th, 2024, and most recently updated on June 9th, 2026. The new information includes updating GENESIS64 and ICONICS Suite affected and fixed versions. 


For more information on these advisories, as well as a DTRH look at a Rockwell exploit and 3 other Rockwell advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published-24b - subscription required. 

House Passes HR 5174 – Technical Update to 51 USC

Yesterday, the House took up HR 5147, the revision of Title 51, United States Code, National and Commercial Space Programs, under the suspension of the rules process. After 21 minutes of debate, the bill was passed by a voice vote. The bill revises 51 USC to keep the Title current and make technical corrections to improve the USC.  

Subsection 2(b) explains the scope of the changes being made:  

The restatement of existing law enacted by this Act does not change the meaning or effect of the existing law. The restatement incorporates in title 51, United States Code, various provisions that were enacted separately over a period of years, reorganizing them, conforming style and terminology, modernizing obsolete language, and correcting drafting errors. These changes serve to remove ambiguities, contradictions, and other imperfections, but they do not change the meaning or effect of the existing law or impair the precedential value of earlier judicial decisions or other interpretations. 

The bill will most likely be handled similarly in the Senate, where it would be considered under the unanimous consent process. However, a similar bill, HR 7339, was introduced and similarly passed in the House in December of 2024, but no action was taken in the Senate. 

Short Takes – 9-1-26 - Federal Register Edition

NEPA  

National Environmental Policy Act Regulations. DOT/FHWA/FRA/FTA final rule. Summary: “FHWA, FRA, and FTA (collectively referred to as the “Agencies”) are finalizing the interim final rule (IFR) published on July 3, 2025, which revised the Agencies' National Environmental Policy Act (NEPA) of 1969 implementing regulations in light of the removal of the Council on Environmental Quality (CEQ) regulations, the amendments to NEPA included in the section of the Fiscal Responsibility Act (FR Act) of 2023, known as the Building United States Infrastructure through Limited Delays and Efficient Reviews (BUILDER) Act of 2023, amendments regarding efficient environmental reviews included in the Infrastructure Investment and Jobs Act (IIJA) of 2021, and the Supreme Court decision in Seven County Infrastructure Coalition. The Agencies provided a 30-day comment period for the public to review and comment on the IFR. This final rule addresses public comments received and finalizes the IFR with minor technical changes. 

Pipeline Safety  

Pipeline Safety: Joint Meeting of the Gas and Liquid Pipeline Advisory Committees. PHMSA comment period extension. Summary: “On July 17, 2026, PHMSA published a Federal Register notice titled: “Pipeline Safety: Joint Meeting of the Gas and Liquid Pipeline Advisory Committees,” which provided an opportunity for public comment by August 31, 2026, on the proceedings of the Gas and Liquid Pipeline Advisory Committees meeting related to 13 notices of proposed rulemakings (NPRM). These proposed rules covered topics such as special permit conditions, in-plant piping, incidental gathering lines, coating damage assessments, atmospheric corrosion, class change pressure tests, maximum allowable operating pressure reconfirmation, operator identification notifications, limitations on welding, remote valves, the property damage definition, right-of-way patrols, and reporting deadlines. PHMSA received requests from stakeholders to extend the comment period. Based on those requests, PHMSA is reopening the comment period for the joint Pipeline Advisory Committee (PAC) proceedings related to the 13 regulatory modernizing NPRMs to September 4, 2026. 

Surface Transportation Security  

Revision of Agency Information Collection Activity Under OMB Review: Cybersecurity Measures for Surface Modes. 30-day ICR revision notice. Summary: “The ICR describes the nature of the information collection and its expected burden. The collection involves the designation of a Cybersecurity Coordinator; the reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency; the development of a cybersecurity contingency/recovery plan to address cybersecurity gaps; and the completion of a cybersecurity assessment. 

NOTE: Today’s notice reports that “After publishing the 60-day notice (link added), TSA reviewed and updated the number of respondents from 846 to 67 and updated the estimate of the annual time burden from 210,684 hours to 22,167 hours.” I will be taking a detailed look at the changes once TSA submits their data to OIRA. 

 
/* Use this with templates/template-twocol.html */