CVE-2021-22681 CVSS Score: 9.8 / 10 (Authentication bypass in Rockwell Logix controllers — no vendor patch available)
On July 26 and 27, a coordinated cyberattack hit more than 30 community water systems across Minnesota. In Braham, population 1,700, the water treatment plant went offline entirely. Operators at other utilities found automated controls unresponsive, switched to manual operation, and began troubleshooting what turned out to be simultaneous, deliberate intrusions across dozens of facilities in a 48-hour window.
Minnesota IT Services confirmed the attacks in a statement on July 28. The FBI acknowledged it was in contact with victims. Drinking water remained safe. No city asked residents to change usage. By the metrics of catastrophe, this was a near miss.
By the metrics that matter for infrastructure security, it was something worse: a proof of concept at scale.
The vulnerability the vendor cannot fix
The attacks targeted programmable logic controllers — PLCs — the embedded computers that open valves, dose chemicals, and monitor pressure in physical infrastructure. Federal investigators have not formally attributed the Minnesota incidents, but the timing, methods, and targets align closely with activity documented in CISA Advisory AA26-097A, which tracks Iranian-affiliated actors exploiting internet-facing PLCs manufactured by Rockwell Automation, Schneider Electric, and Siemens.
The lead vulnerability is CVE-2021-22681, a CVSS 9.8 authentication bypass in Rockwell Automation's Logix controllers caused by an insufficiently protected cryptographic key. It was disclosed in 2021. It remains unpatched in 2026 — not because the vendor is slow, but because the flaw is architectural. Fixing it would require changes that break backward compatibility across the installed base. The vulnerability is not a bug. It is a design consequence that the vendor has chosen to manage rather than eliminate.
Two additional CVEs compound the exposure: CVE-2023-3595, a CVSS 9.8 remote code execution flaw in ControlLogix communication modules, and CVE-2024-6242, a CVSS 8.4 bypass of the Trusted Slot security feature meant to restrict lateral movement between modules. Together, they form a chain: bypass authentication, execute code, move laterally — on controllers that were never designed to face the internet and now do.
What the attackers actually did
The CISA advisory, updated on July 22 — four days before the Minnesota attacks — documents the operational playbook. Attackers used vendor engineering software hosted on third-party infrastructure to connect to exposed PLCs. Once connected, they exfiltrated project files containing the controller's logic and configuration. Then they modified Add-On Instructions (AOIs) — reusable code modules embedded in PLC programs — to alter how physical processes behave.
The subtlest technique was HMI manipulation: changing what operators see on their screens while the underlying process runs differently. Pressure readings that look normal. Chemical dosing that appears correct. Alarms that never fire. The advisory documents attackers disabling critical shutdown sequences and alarm systems, allowing equipment to operate in unsafe conditions without alerting the humans nominally in control.
This is not ransomware. Nobody encrypted a file and demanded Bitcoin. This is process manipulation — changing the physics of what a water plant does while its operators watch dashboards that lie to them.
The exposure is structural, not incidental
Censys scanning identified 5,219 internet-exposed hosts globally responding to industrial protocols and self-identifying as Rockwell Automation devices. Nearly three-quarters — 74.6% — are in the United States, representing roughly 3,891 exposed controllers. Each one is a potential entry point to a physical process: water treatment, power distribution, manufacturing.
These devices are not exposed because someone misconfigured a firewall. They are exposed because small utilities, lacking IT staff and budget, connected PLCs to the internet for remote monitoring and maintenance. The connectivity was the feature. The attack surface was the architecture decision.
The EPA warned in 2024 that more than 70% of U.S. water systems were failing to comply with risk assessment requirements established in 2018. An audit of 1,000 systems found 97 with critical or high-risk vulnerabilities. The United States operates between 150,000 and 170,000 water systems, the vast majority small, rural, and running on budgets that do not include a line item for cybersecurity.
The pattern behind the pattern
The actors behind this campaign operate under multiple tracking names — CyberAv3ngers, Storm-0784, Bauxite, UNC5691, MITRE G1027 — all attributed to Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). Their earlier campaign, between November 2023 and January 2024, targeted Unitronics PLCs at water facilities in four separate waves. The current campaign, documented from September 2025 through July 2026, expanded to Rockwell, Schneider Electric's Modicon M340 line, and Siemens S7-1200 series controllers.
The escalation follows a clear logic: each wave targets a broader set of vendors, exploits a wider range of protocols, and hits more facilities simultaneously. The April 7 advisory covered Rockwell. The July 22 update added Schneider and Siemens. Five days later, 30 systems went down in Minnesota. The advisory described what was coming. The infrastructure could not move fast enough to respond.
The proliferation is the operational risk. CISA's reporting documents more than 60 affiliated hacktivist groups adopting CyberAv3ngers' exploitation techniques through an operational coordination structure the agency calls the Electronic Operations Room. When a technique works at scale on unpatchable devices, it does not stay with one actor. It becomes a commodity.
What this means for infrastructure decisions
WebPulse tracks the consequences of technology choices across digital infrastructure — which frameworks accumulate CVEs, which architectures resist exploitation, where technical debt compounds into operational risk. The Minnesota water attacks illustrate the same pattern in physical infrastructure that we document in digital: legacy systems do not fail because they are old. They fail because the assumptions they were built on — that PLCs would never face the internet, that obscurity provided security, that small utilities would never be targeted — expired, and the architecture could not adapt.
CVE-2021-22681 is the PLC equivalent of a structural web framework vulnerability: embedded so deeply in the architecture that fixing it means rebuilding the system. The 70% noncompliance rate is the critical-infrastructure version of the unpatched WordPress installation. The 48-hour coordinated attack is what happens when adversaries automate target selection against a target-rich environment that cannot respond at machine speed.
The question Minnesota just answered is whether coordinated attacks on distributed small utilities are operationally feasible. They are. The question still open is whether the 150,000 other water systems in the country will update their architecture before the next wave — or whether the next advisory will describe what happens when attackers stop manipulating displays and start manipulating chemistry.





