← Back to Feed

Coordinated “cyberattack” on Minnesota water utilities: What you need to know

CVE-2021-22681

July 29, 2026 · Tenable Blog · Severity: CRITICAL

A coordinated cyberattack targeted water and wastewater systems across more than 30 Minnesota communities on July 26-27, 2026, with attribution pending investigation. The attack aligns with Iranian-affiliated PLC exploitation activity documented in CISA Advisory AA26-097A, which expanded to include Schneider Electric and Siemens devices and noted exploitation of CVE-2021-22681.

Key Takeaways

  • A coordinated cyberattack disrupted water systems across more than 30 Minnesota communities in July 2026.
  • CISA advisory AA26-097A expanded to include Schneider Electric and Siemens devices alongside Rockwell Automation.
  • CVE-2021-22681, a critical authentication bypass in Rockwell Logix controllers, was exploited by Iranian-affiliated actors.
☕ Buy a Coffee