Back to Feed
PolicySep 25, 2026

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

CISA's 2026 Election Security Plan highlights patching barriers and voter database threats.

Summary

CISA's 2026 Election Infrastructure Security Plan identifies key cyber threats to US elections, including vulnerabilities in election software hindered by certification processes and the risk of attacks on voter registration databases. The plan emphasizes improving cyber hygiene, implementing multi-factor authentication, and addressing insider risks, while also recommending changes to the software certification ecosystem to allow for faster patching.

Full text

The US Cybersecurity and Infrastructure Security Agency (CISA) has published its 2026 Election Infrastructure Security Plan, which describes the cyber and physical threats facing election systems and the free services CISA offers to election officials and other partners. Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. State and local election officials have primary responsibility for protecting election infrastructure, with more than 10,000 local jurisdictions managing elections. The federal government, including CISA, provides information, tools, and resources to help. Certification rules can hold back patching According to CISA, election software can contain vulnerabilities that need to be fixed promptly. However, the agency notes that “structural constraints within the certification ecosystem can significantly limit vendors’ ability to release patches and prevent system owners from applying them quickly.” CISA’s assessments also show that state, local, tribal and territorial (SLTT) election offices often struggle with basic cyber hygiene and vulnerability remediation. In addition, election infrastructure is often accessible from general enterprise networks. Attackers who compromise email systems or workstations can use that access to move laterally. The agency names three issues, including vulnerability management limited by outdated certification regimes, inconsistent vendor transparency about vulnerabilities and patch status, and the cybersecurity immaturity of many SLTT networks that host election systems.Advertisement. Scroll to continue reading. CISA recommends aligning patch management with certification requirements, so that security updates can be applied in real time without affecting system certification. It also recommends paper ballots and manual post-election audits. The agency suggests that election officials encourage software providers to assign CVE identifiers to flaws, tell customers promptly if source code is leaked or stolen, report incidents to authorities, and ship a software bill of materials (SBOM) with every product. Voter registration databases remain a target Citing reports from the past decade, CISA says voter registration databases are attractive targets for foreign adversaries. “Hackers have attempted to breach voter registration systems in all 50 states, with confirmed success in at least 20 states,” CISA says. To protect these databases, the plan prioritizes multi-factor authentication, network monitoring to spot anomalies, limiting access to what each user needs for their job, retaining critical logs for at least a year, and keeping the online registration and lookup tools used by the public walled off from the master database. Insider risks span staff, volunteers and vendors CISA says insider risk is a growing concern that involves permanent staff, temporary or seasonal workers, volunteer poll workers, contractors and vendors. Seasonal and volunteer personnel may not undergo the same vetting as permanent staff. According to CISA, malicious insiders could make unauthorized changes to voter registration databases, ballot definitions, tabulation settings or results reporting, while careless ones could fall for phishing, plug unauthorized removable media into election systems or mishandle equipment. Practices such as bipartisan two-person ballot handling, counting observers and chain-of-custody procedures were designed to reduce this risk. CISA says election offices benefit from formalizing them into a documented insider threat program. Addressing physical risks, CISA noted that 96 of the 107 election-related security incidents tracked through open source reporting since January 2022 were bomb threats. Information-sharing platform for the 2026 cycle For the 2026 election cycle, CISA is supporting a no-cost information-sharing platform for all fusion centers and state and local election officials. The platform supports near real-time communication with peers and federal partners. “This model was successfully deployed and utilized during FIFA World Cup 2026,” the agency notes. The plan also highlights free services, including vulnerability and web application scanning, continuous penetration testing, risk and vulnerability assessments, and decoy systems and canary tokens for detecting intrusions. Related: OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators Related: CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses Related: CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorsUS Court Sentences Armenian Man to Prison for Ryuk Ransomware AttacksHoneywell: OT Security Teams Embrace AI, but Autonomy Still RareAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityOnly 13% of OT Network Segments Are Fully Isolated: AnalysisJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme Latest News Kosovar Owner of Rydox Marketplace Pleads Guilty in US CourtWindows, Linux, Android File Notification Systems Leak User Activity‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data ExfiltrationRoundcube Webmail Vulnerability in Attackers’ CrosshairsAutonomous AI Hacks Raise Thorny Questions of Legal AccountabilityKontext Security Emerges With $4 Million for AI Agent Runtime ControlsOpenAI Agents Probed Websites for Vulnerabilities While Fetching Public DataAI-Powered Campaign Targets Hundreds of Online Retailers Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must trea

Entities

CISA (vendor)Election Infrastructure Security Plan (product)Voter registration databases (technology)Software Bill of Materials (SBOM) (technology)