Friday, July 31, 2026

Chemical Transportation Incidents – Week of 6-27-26

Reporting Background 

See this post for explanation, with the most recent update here (removed from paywall). 

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency. 

Incidents Summary  

• Number of incidents – 544 (521 highway, 16 air, 7 rail, 0 water) 

• Serious incidents – 8 (6 Bulk release, 2 evacuation, 0 injury, 0 death, 2 major artery closed, 2 fire/explosion, 29 no release)  

• Largest container involved – 33,980-gal DOT 112J340W Railcar {Butane See Also Petroleum Gases, Liquefied} Overloaded and overpressure due to ambient heating. 

• Largest amount spilled – 500-gal DOT 111A100W1 Railcar {Ammonium Nitrate, Liquid (Hot Concentrated Solution)} Corrosion hole in tank and liner. 

• Total amount reported spilled in all incidents – 3163.5-gal 

NOTE: Links above are to Form 5800.1 for the described incidents. 

Most Interesting Chemical: Pyrethroid Pesticide, Liquid Toxic: Pyrethroid Pesticide, Liquid, TOXIC is an insecticidal liquid consisting either of a single pyrethroid or a mixture of pyrethroids or a solution of such a pyrethroid or mixture dissolved in a organic solvent having a flash point exceeding 100°F. A pyrethroid pesticide is a substance possessing the terpenoid structure and insecticidal properties that are characteristic of the pyrethrins. The pyrethrins are terpenoid esters that are obtained from flower heads of the chrysanthemum and related species or by synthesis. The most prominent are pyrethrin I (C21H28O3) and pyrethrin II (C22H28O5 ) which are the major active ingredients in pyrethrum powder. Both of these compounds are water-insoluble oily liquids. The insecticide/carrier mixture is toxic by inhalation, ingestion, and skin absorption. (Source: CameoChemicals.NOAA.gov).  


Review - PHMSA in the Federal Register – 7-31-26

 Today, DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) published 17 actions in the Federal Register. These actions refer to Federal Register publications from April 24th, 2026; not all of the actions published on that day were addressed in today’s Federal Register. They include: 

  • Direct final rule (DFR) withdrawals (2),  
  • DFR date confirmations (15).  

Direct Final Rule Withdrawals  

When DOT direct final rules are issued, that issuance is subject to the ‘adverse comment’ exception found in 49 CFR 190.339(c). If an adverse comment is received on the DFR within the comment period, in the case of these two DFR’s June 23rd, 2026, then the DFR will be withdrawn and the responsible agency will decide whether to proceed with a revised DFR, initiate a more conventional rulemaking, or abandon the process completely. 

The two DFR withdrawals published today were:  


For more information on the DFR date confirmations, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/phmsa-in-the-federal-register-7-31 - subscription required. Free subscribers will receive email copies of that post tomorrow. 

Personal Note: The Chief Counsel, Keith Coyle, listed in each of these rulemaking notices is, to the best of my knowledge, not related to me. 

Thursday, July 30, 2026

Review – 11 Advisories and 1 Update Published – 7-30-26

Today CISA’s NCCIC-ICS published 11 control system security advisories for products from MZ Automation (2), Watchfire, 06 Automation, Mitsubishi Electric, NASA, Rockwell Automation, Schneider Electric, Toptech, Johnson Controls, and MikroTik. They also updated an advisory for products from Hardy Barth. 

Advisories  

MZ Automation Advisory #1 - This advisory describes two vulnerabilities in the MZ Automation lib60870. 

MZ Automation Advisory #2 - This advisory describes eight vulnerabilities in the MZ Automation GmbH libiec61850. 

Watchfire Advisory - This advisory describes a hard-coded cryptographic key vulnerability in the Watchfire Controller Software. 

06 Automation Advisory - This advisory describes four vulnerabilities in the o6 Automation open62541 OPC UA stack. 

Mitsubishi Advisory - This advisory describes an improper enforcement of message integrity during transmission in a communication channel vulnerability in the Mitsubishi CC-Link IE TSN Communication Protocol. 

NASA Advisory - This advisory describes a NULL pointer dereference vulnerability in the NASA Core Flight System (cFS) Health & Safety (HS) Application. 

NOTE: This vulnerability is related to an incomplete fix for CVE 2026-15352. 

Rockwell Advisory - This advisory describes an improper check for certificate revocation vulnerability in the Rockwell CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module. 

Schneider Advisory - This advisory describes an out-of-bounds write vulnerability in the Schneider IGSS. 

Toptech Advisory - This advisory describes a missing authentication for critical function vulnerability in the Toptech Systems RCU II+ and Multiload II+. 

Johnson Controls Advisory - This advisory describes three vulnerabilities in the Johnson Controls OpenBlue Employee smart building ecosystem. 

MikroTik Advisory - This advisory describes an insufficient session expiration vulnerability in the MikroTik RouterOS. 

Updates  

Hardy Barth Update -  This update provides additional information on the Salia EV Charge Controller advisory that was originally published on April 21st, 2026. 


For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/11-advisories-and-1-update-published-68f  - subscription required. 

 
/* Use this with templates/template-twocol.html */