← Back to Feed
Coordinated “cyberattack” on Minnesota water utilities: What you need to know
CVE-2021-22681
July 29, 2026 · Tenable Blog · Severity: CRITICAL
A coordinated cyberattack targeted water and wastewater systems across more than 30 Minnesota communities on July 26-27, 2026, with attribution pending investigation. The attack aligns with Iranian-affiliated PLC exploitation activity documented in CISA Advisory AA26-097A, which expanded to include Schneider Electric and Siemens devices and noted exploitation of CVE-2021-22681.
Key Takeaways
- A coordinated cyberattack disrupted water systems across more than 30 Minnesota communities in July 2026.
- CISA advisory AA26-097A expanded to include Schneider Electric and Siemens devices alongside Rockwell Automation.
- CVE-2021-22681, a critical authentication bypass in Rockwell Logix controllers, was exploited by Iranian-affiliated actors.