CISA election software patch-management certification guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CISA issued guidance for election software that aligns patch management with certification requirements so security updates can be deployed in real time without breaking certification. The recommendation reduces delay in fixing vulnerabilities across the election infrastructure ecosystem. It directly addresses a remediation bottleneck that can leave vulnerable systems exposed longer than necessary.
Related Happenings
CISA election registration database hardening guidance for election offices
Defensive Guidance
H score39
First: 25.09.2026 15:39
Last: 25.09.2026 15:39
Sources 1
How related:
To protect these databases, the plan prioritizes multi-factor authentication, network monitoring to spot anomalies, limiting access to what each user needs for their job, retaining critical logs for at least a year, and keeping the online registration and lookup tools used by the public walled off from the master database.
About this happening:
Election infrastructure guidance now prioritizes multi-factor authentication, network monitoring, and least-privilege access for voter registration databases, redu...
CISA election registration database hardening guidance for election offices
Defensive GuidanceHow related: To protect these databases, the plan prioritizes multi-factor authentication, network monitoring to spot anomalies, limiting access to what each user needs for their job, retaining critical logs for at least a year, and keeping the online registration and lookup tools used by the public walled off from the master database.
About this happening: Election infrastructure guidance now prioritizes multi-factor authentication, network monitoring, and least-privilege access for voter registration databases, redu...
CISA publishes 2026 Election Infrastructure Security Plan
Public Sector Action
H score50
First: 25.09.2026 15:39
Last: 25.09.2026 15:39
Sources 1
How related:
The US Cybersecurity and Infrastructure Security Agency (CISA) has published its 2026 Election Infrastructure Security Plan, which describes the cyber and physical threats facing election systems and the free services CISA offers to election officials and other partners.
About this happening:
CISA published its 2026 Election Infrastructure Security Plan, adding cyber and physical threat guidance and free services for election officials and partners. The pla...
CISA publishes 2026 Election Infrastructure Security Plan
Public Sector ActionHow related: The US Cybersecurity and Infrastructure Security Agency (CISA) has published its 2026 Election Infrastructure Security Plan, which describes the cyber and physical threats facing election systems and the free services CISA offers to election officials and other partners.
About this happening: CISA published its 2026 Election Infrastructure Security Plan, adding cyber and physical threat guidance and free services for election officials and partners. The pla...
CISA Election Infrastructure Security Plan for the 2026 midterms
Public Sector Action
H score18
First: 25.09.2026 15:30
Last: 25.09.2026 15:30
Sources 1
About this happening:
CISA published an Election Infrastructure Security Plan for state, local, tribal, and federal election bodies ahead of the November 2026 midterms. The plan adds a...
CISA Election Infrastructure Security Plan for the 2026 midterms
Public Sector ActionAbout this happening: CISA published an Election Infrastructure Security Plan for state, local, tribal, and federal election bodies ahead of the November 2026 midterms. The plan adds a...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...
CISA-led joint advisory to secure internet-exposed ATG systems
Public Sector Action
H score43
First: 05.06.2026 17:50
Last: 05.06.2026 17:50
Sources 1
About this happening:
On 2026-06-05, CISA, the FBI, the NSA, the Department of Energy, and other U.S. partners issued a joint advisory telling critical infrastructure organiza...
CISA-led joint advisory to secure internet-exposed ATG systems
Public Sector ActionAbout this happening: On 2026-06-05, CISA, the FBI, the NSA, the Department of Energy, and other U.S. partners issued a joint advisory telling critical infrastructure organiza...
Timeline
-
25.09.2026 15:39 2 articles · 2h ago
CISA publishes election software patch-management guidance
Mitigation Patch UpdateCISA published the 2026 Election Infrastructure Security Plan and recommended aligning patch management with certification requirements so security updates can be applied in real time without affecting system certification. The plan also highlights free services for election officials, including vulnerability and web application scanning, continuous penetration testing, risk and vulnerability assessments, and decoy systems and canary tokens.
Show sources
- CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks — www.securityweek.com — 25.09.2026 15:39
- CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks — www.securityweek.com — 25.09.2026 15:39