Thursday, September 10, 2026

Review – 3 Advisories and 1 Update Published – 9-10-26

Today CISA’s NCCIC-ICS published one control system security advisory for products from AVEVA, and two medical device security advisories for products from Orthanc and NextGen. They also updated a control system advisory for products from ST Engineering. 

Advisories  

Aveva Advisory - This advisory describes four vulnerabilities in the AVEVA Pipeline Integrity Monitor. Two of the vulnerabilities were reported by Adham Khairy Ramadan via HackerOne. 

Orthanc Advisory - This advisory describes an integer overflow or wraparound vulnerability in the Orthanc DICOM Server. The vulnerability was reported to CISA by Andrej Tomci 

NextGen Advisory - This advisory describes three vulnerabilities in the NextGen Healthcare Mirth Connect. The vulnerabilities were reported to CISA by Abhinav Agarwal  

Updates  

ST Engineering Update - This update provides additional information on the iDirect iQ-Series Terminals advisory that was originally on July 2nd, 2026. The new information includes adding two vulnerabilities. 


For more information on these advisories, including DTRH looks at exploits in the wild and POC, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published-091 - subscription required. 

Review - S 5067 Introduced – Cybersecurity Training

Back in July, Sen Hassan (D,NH) introduced S 5067, the Federal Cybersecurity Workforce Expansion Act. It would require CISA to establish an apprenticeship program that would lead to cybersecurity related employment with CISA or other Federal entity. The bill would also require the Veterans Administration to establish a pilot program providing cyber-specific training for eligible individuals. There is no funding authorized in the legislation. 

S 5067 is very similar to S 2256, the Federal Cybersecurity Workforce Expansion Act, that was introduced by Hassan in July 2023. The Senate Homeland Security and Governmental Affairs Committee held a business meeting on July 26th, 2023, and ordered the bill reported favorably by a vote of 7 to 1 {Sen Paul (R,KY) voting NAY}. No further action was taken on the bill in the 118th Congress. A similar bill, HR 6524, was introduced in the Housse by Rep Houlahan (D,PA) in November of 2023. No action was taken on that bill in the House. 

Moving Forward 

Hassan is a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. That means that there may be enough influence to see this bill considered by the Committee. Having said that, because the current Chair of the Committee, Sen Paul (R,KY), voted against a nearly identical bill last session, it is unlikely that S 5067 will be considered in this session. 

Commentary 

While this bill does not directly address control system security issues, increasing the cybersecurity qualified staffing of CISA is certainly of interest to the ICS security community. While the training programs established under this bill would be targeted at future CISA employment, they should result in a net increase to the nation’s cybersecurity workforce. 


For more information on the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-5067-introduced-cybersecurity-training-b39 - subscription required. 

CISA Adds FortiGuard Vulnerability to KEV Catalog – 9-9-26

Yesterday, CISA announced that it had added a heap-based buffer overflow vulnerability in the FortiGuard FortiOS and FortiSwitchManager products to their Known Exploited Vulnerabilities (KEV) catalog. FortiGuard published their advisory on the vulnerability in January 2026, and most recently updated it in February. Fixed versions are available. 

On Tuesday, SOCRadar published an article detailing their discovery of the “PivotC2, a Node.js Remote Access Trojan (RAT) designed specifically as a FortiGate post-exploitation tool.” They report seeing evidence of exploits in the wild as far back as July of this year. The article provides a detailed technical analysis of the fortirun.bin component of PivotC2 as well as indicators of compromise. 

CISA has directed federal agencies using the affected FortiGuard products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

A compliance deadline of September 12th, 2026 has been established. 

Short Takes – 9-10-26 - Federal Register Edition

HAZMAT Safety  

Hazardous Materials: California's Reusability Mandate for Propane Cylinders. PHMSA preemption notification notice. Summary: “The Federal Hazardous Materials Transportation Act (HMTA), 49 U.S.C. 5101 et seq., preempts California's reusability mandate for propane cylinders in California Public Resources Code, Sections 42395-42395.2. The reusability mandate imposes localized design and manufacturing requirements on a container that is represented, marked, certified, or sold as qualified for use in the transportation of a hazardous material—specifically, propane—that are not substantively the same as the requirements in the HMR. The reusability mandate is also an obstacle to accomplishing and carrying out the HMTA. By banning a federally authorized, safety-compliant packaging based on localized waste management preferences, California creates a fragmented regulatory patchwork that undermines the primacy and uniformity of the Federal transportation safety framework. 

Information Collection Requests  

Proposed Renewal Collection and Request for Comment; Regulation of Persistent, Bioaccumulative, and Toxic Chemicals Under TSCA Section 6(h). EPA 60-day ICR renewal notice. 

Proposed Renewal Collection and Request for Comment; User Fees for the Administration of the Toxic Substances Control Act (TSCA). EPA 60-day ICR renewal notice. 

State, Local, Tribal and Private Sector (SLTPS) Clearance Request Form (Form 9014) Submission to the Office of Management and Budget for Review and Approval; Comment Request. CISA 60-day ICR revision notice. 

Executive Orders  

EO 14424 - Promoting Fair Competition in Livestock Markets and Expanding Market Access for American Meat Producers. 

EO 14425 - Supporting America's Ranchers. 

 
/* Use this with templates/template-twocol.html */