Cybersecurity Bulletin: Key Security Updates for Water & Wastewater Utilities
August 27, 2026
Member Security Bulletin
Federal cybersecurity agencies and water sector partners continue to report increased cyber activity affecting critical infrastructure. Below are the most important updates for Utah water and wastewater utilities.
High Priority
Oracle Vulnerability Under Active Exploitation
A critical vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in is currently being actively exploited in the wild.
Recommended Actions- Determine whether your organization uses Oracle HTTP Server or Oracle WebLogic.
- Apply available vendor security updates immediately if affected.
- Monitor systems for unusual activity until patching has been completed.
China-Linked Threat Group Targeting Critical Infrastructure
The FBI, NSA, and U.S. Cyber National Mission Force released a joint cybersecurity advisory regarding ongoing activity from a China-linked threat group targeting U.S. critical infrastructure.
Recommended Actions- Review the advisory with your IT provider.
- Verify multi-factor authentication is enabled for all remote access.
- Review privileged accounts and administrative access.
Ongoing PLC Cyber Activity
Federal cybersecurity partners continue monitoring cyber activity targeting programmable logic controllers (PLCs) used throughout the water and wastewater sector.
Recommended Actions- Verify PLCs and industrial control system devices are not directly accessible from the public internet.
- Review any cellular modem or remote access configurations.
- Monitor control systems for unauthorized access or unexpected configuration changes.
Additional Updates
Kennedy Jenks Ransomware Incident
Kennedy Jenks has released additional information regarding the recent ransomware incident. Utilities currently working with Kennedy Jenks should remain aware of the situation and follow any guidance provided directly by the company.
Micro-Comm Ransomware Incident
WaterISAC reported that Micro-Comm Inc. has been identified as a potential ransomware victim. Utilities utilizing Micro-Comm products or services should monitor communications from the company for additional guidance.
EPA Releases Drinking Water Systemic Issues Checklist
EPA has released a new checklist to help drinking water agencies identify recurring operational issues before they impact service reliability. The resource may be useful during internal reviews and planning efforts.
New CISA ICS Advisories Available
CISA has published additional Industrial Control System security advisories affecting multiple vendors and products. Utilities should work with their IT and SCADA providers to determine whether any advisories apply to their environment.
Report Suspicious Activity
If your utility experiences suspicious cyber activity or a confirmed cyber incident, report it immediately using the resources below.
Utah Cyber Center
Report a Cyber Incident →Utah Division of Drinking Water
24/7 Emergency Response Line
(801) 560-8456