Friday, September 4, 2026

Short Takes – 9-4-26 - Federal Register Edition

TSCA  

1,2-Dichloropropane Draft Risk Evaluation Under the Toxic Substances Control Act (TSCA); Notice of Availability and Request for Comment. EPA, notice of availability. Summary: “The Environmental Protection Agency (EPA or Agency) is announcing the availability of and seeking public comment on a draft risk evaluation under the Toxic Substances Control Act (TSCA) for 1,2-dichloropropane. The purpose of risk evaluations under TSCA is to determine whether a chemical substance presents an unreasonable risk of injury to health or the environment under the conditions of use (COUs), including unreasonable risk to potentially exposed or susceptible subpopulations identified as relevant to the risk evaluation by EPA, and without consideration of costs or non-risk factors. EPA is seeking comment on the draft risk evaluation for 1,2-dichloropropane. 

Port Security  

Agency Information Collection Activities: Proposed Collection, Comment Request; FEMA Preparedness Grants: Port Security Grant Program (PSGP). FEMA 60-day ICR extension notice. Summary: “Section 102 of the Maritime Transportation Security Act of 2002, as amended (46 U.S.C. 70107 [link added]), authorizes the PSGP to provide for the risk-based allocation of funds to implement Area Maritime Transportation Security Plans and facility security plans among port authorities, facility operators, and State and local government agencies required to provide port security services and to train law enforcement personnel under 46 U.S.C. 70132. Before awarding a grant under the program, the Secretary for Homeland Security shall provide for review and comment by the appropriate Federal Maritime Security Coordinators and the Maritime Administrator. In administering the grant program, the Secretary shall consider national economic, energy, and strategic defense concerns based upon the most current risk assessments available.” 

UAS Security  

Notice Soliciting Representatives for Technical Roundtables on Security of Unmanned Aircraft Systems Operating Beyond the Visual Line of Sight. TSA notice. Summary: “The Transportation Security Administration (TSA) is soliciting individuals to participate in technical roundtables that will provide input to TSA relevant to the development of model language for TSA-approved security programs that will provide for the secure operation of unmanned aircraft systems (UAS) beyond visual line of sight (BVLOS). These roundtables will be closed to the public. Participation is limited and all participants must be validated by TSA as a representative of either a UAS BVLOS operator or an industry association representing these operators or subset of operators, as discussed later in this notice. Participants must obtain approval from TSA for access to Sensitive Security Information (SSI).” 

Space Geek  

Name of Information Collection: NASA Visitor Management System (NVMS). NASA 30-day ICR revision notice. Summary: “NASA may collect event registration information to include but not limited to a visitor's name, address, citizenship, biometric data, purpose of visit, the location to be visited, escort/sponsor name with contact data, and preferred meeting/event sessions when options are available. When parking is provided on federally owned/leased space, driver's license information as well as vehicle make/model/tag information will be collected.” 

Notice of Availability on the Final Tiered Environmental Assessment and Finding of No Significant Impact for SpaceX Starship Reentry Contingency Operations in the Pacific Ocean and Additional Starship Landing Trajectory. FAA notice of availability. Summary: “In accordance with the National Environmental Policy Act of 1969, as amended (NEPA), DOT Order 5610.1D, DOT's Procedures for Considering Environmental Impacts, and FAA Order 1050.1G,  FAA National Environmental Policy Act Implementing Procedures, the FAA is announcing the availability of the Final Tiered Environmental Assessment and Finding of No Significant Impact/Record of Decision for SpaceX Starship Reentry Contingency Operations in the Pacific Ocean and Additional Starship Landing Trajectory (Final Tiered EA and FONSI/ROD). 

Chemical Transportation Incidents – Week of 8-1-26

Reporting Background 

See this post for explanation, with the most recent update here (removed from paywall). 

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency. 

Incidents Summary  

  • Number of incidents – 597 (557 highway, 33 air, 7 rail, 0 water) 
  • Serious incidents – 2 (1 Bulk release, 0 evacuation, 0 injury, 0 death, 0 major artery closed, 1 fire/explosion, 28 no release)  
  • Largest container involved – 29,989-gal DOT 111A100W1 Railcar {Petroleum Distillates, N.O.S. or Petroleum Products, N.O.S.} deteriorated bottom outlet cap gasket and a BOV closure cap being less than tool-tight. 
  • Largest amount spilled – 308-gal Railcar (CIMX 2134) {Environmentally Hazardous Substances, Liquid, N.O.S.} [UI] lose bolts tightened on 3 separate occasions. 
  • Total amount reported spilled in all incidents – 1987.5-gal 

NOTE: Links above are to Form 5800.1 for the incident described. 

Most Interesting Chemical: Formaldehyde, Solutions (Formalin) (Corrosive): A colorless liquid with a pungent irritating odor. Contains 37-50% formaldehyde by mass and varying amounts of methanol, added to prevent precipitation of formaldehyde polymers (formaldehyde exists in solution as CH2(OH)2 and its polymers HO(CH2O)xH where x averages about three). Formalin free of methanol is also shipped but must be kept warm (about 30°C (86°F)) to prevent polymerization. Pure formaldehyde, a gas, is not handled commercially because it tends to polymerize exothermally and may ignite. Vapor from formalin solution is flammable and an explosion hazard when exposed to flame or heat. Skin and eye irritant. Confirmed carcinogen(Source: CameoChemicals.NOAA.gov).  



Thursday, September 3, 2026

HR 7945 Approved in Subcommittee – Nitrous Oxide Safety

Earlier this week, the Subcommittee on Commerce, Manufacturing, and Trade of the House Energy and Commerce Committee held a business meeting that considered 12 pieces of legislation, including HR 7945, the Nitrous Oxide Safety Act of 2026. The bill was forwarded to the full committee with a favorable recommendation by a voice vote. 

The bill would establish that, with certain specified exceptions, a consumer product containing nitrous oxide (NO2) is a banned hazardous product under 15 USC 2057. No new funding is authorized. 

Review – 8 Advisories and 2 Updates Published – 9-3-26

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Tycon Systems, Pyramid Solutions, Inductive Automation, Rockwell Automation (3), IOXN, OPC Foundation. They also updated advisories for products from Tycon Systems and Schneider Electric. 

Advisories  

Tycon Advisory - This advisory describes three vulnerabilities in the Tycon TPDIN-Monitor-WEB3. The vulnerabilities were reported to CISA by Abdiwelli Guled. 

Pyramid Advisory - This advisory discusses a stack-based buffer overflow vulnerability in the Pyramid NetStaX EtherNet/IP Stack. The vulnerability is self-reported. Excellent blog post about the vulnerability on the Pyramid Solutions web site. 

Inductive Advisory - This advisory describes an incorrect default permissions vulnerability in the Inductive Automation Ignition product. The vulnerability was independently reported by Christopher Lusk and Elhussain Fathy. 

Rockwell Advisory #1 - This advisory describes an improper check for unusual or exceptional conditions vulnerability in the Rockwell 1756-ENBT Module. The vulnerability is self-reported. The associated Rockwell advisory has not yet been published. 

Rockwell Advisory #2 - This advisory describes two vulnerabilities in the Rockwell ArmorStart LT. The vulnerabilities are self-reported. 

Rockwell Advisory #3  This advisory describes a missing authentication for critical function vulnerability in the Rockwell ControlFLASH. The vulnerabilities are self-reported. 

IXON Advisory - This advisory describes a CRLF sequence injection vulnerability in the IXON VPN. The vulnerabilities are self-reported. 

OPC Foundation Advisory  This advisory describes an execution with unnecessary privileges vulnerability in the OPC Foundation OPC UA LocalDiscoveryServer (LDS). The vulnerability was reported by Lukas Schumaker of Rockwell Automation. 

Update Summaries  

Tycon Update - This update provides additional information on the TPDIN-Monitor-WEB2 advisory that was originally published on July 21st, 2026. The new information includes updating the affected version range and vulnerability details based on vendor input. 

Schneider Update - This update provides additional information on the Easergy advisory that was originally published on June 18th, 2026. The new information includes revising the summary to reflect the affected products 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-2-updates-published-435 - subscription required. 

 
/* Use this with templates/template-twocol.html */