Critical

Security Vulnerability in a Voting System

Schneier on Security
Actively Exploited

Overview

A recently exploited vulnerability in a voting system has raised concerns about the integrity of elections in Georgia, which utilizes affected ballot scanners. This flaw, first disclosed nearly four years ago, allows individuals to deduce the order in which ballots were cast without needing to access any voting machines or private networks. Using publicly available data, including early-voting lists and cast-vote record files, a researcher successfully analyzed voter behavior during the May 2026 primary. The ability to reconstruct ballot order poses risks to voter privacy and the overall transparency of the electoral process, highlighting the need for enhanced security measures in voting technologies. As this vulnerability is actively being exploited, it’s crucial for election officials to address these weaknesses promptly to safeguard future elections.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Voting systems in Georgia, specifically those using affected scanners.
  • Action Required: Election officials should assess and update voting systems to mitigate this vulnerability, potentially including software patches or hardware upgrades as necessary.
  • Timeline: Disclosed on [date of original disclosure], ongoing since 2019.

Original Article Summary

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but not the voters’ names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable...

Impact

Voting systems in Georgia, specifically those using affected scanners.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on [date of original disclosure], ongoing since 2019.

Remediation

Election officials should assess and update voting systems to mitigate this vulnerability, potentially including software patches or hardware upgrades as necessary.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Vulnerability.

Related Coverage

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News

Recent vulnerabilities in PaperCut have been exploited by attackers to steal credentials from educational institutions in the U.S. and Europe. The Arctic Wolf Adversary Research Team identified two specific vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which allow for authentication bypass and remote code execution. These flaws enable attackers to execute commands and gather information within the affected systems. The impact is particularly significant for schools and universities, as they often handle sensitive student and staff information. Immediate action is essential to prevent unauthorized access and potential data breaches.

Sep 5, 2026

European parliament members call for slowdown of Serbia’s EU entry over spyware use

CyberScoop

Members of the European Parliament are urging a delay in Serbia's entry into the European Union due to concerns over the government's use of spyware against activists. This call comes after reports that Serbian student activists were targeted with the invasive Pegasus and NoviSpy spyware. These revelations have raised alarms about human rights and privacy violations in Serbia, especially in the context of its EU accession talks. The situation reflects broader pressures on the Serbian government regarding its commitment to democratic practices and the protection of civil liberties. The Parliament's stance indicates that future EU membership may depend on significant improvements in these areas.

Sep 4, 2026

HPE Patches Critical RCE Vulnerabilities in AOS-CX

SecurityWeek

Hewlett Packard Enterprise (HPE) has released critical patches to address a series of vulnerabilities in its AOS-CX networking operating system. These vulnerabilities, collectively identified as CVE-2026-73749, carry a high severity score of 9.8, indicating they could allow remote code execution. This means that attackers could potentially exploit these flaws to take control of affected systems from a distance. Organizations using AOS-CX should prioritize applying these updates to safeguard their networks. The vulnerabilities are significant as they could affect a wide range of network devices, potentially putting sensitive data and operations at risk.

Sep 4, 2026

Companies Have 6 Months to Prepare for Automated Attacks

darkreading

Recent advancements in AI technology have enabled automated systems to conduct end-to-end attacks on various digital infrastructures. These AI models can compromise systems either intentionally or inadvertently, raising alarms for organizations that rely on traditional cybersecurity defenses. Experts warn that companies have a six-month window to enhance their security measures in anticipation of these automated threats becoming more prevalent. The urgency lies in the fact that as AI capabilities improve, so does the potential for sophisticated attacks that could bypass existing security protocols. Organizations need to prepare by investing in updated security technologies and protocols to safeguard their data and systems against these emerging risks.

Sep 4, 2026

Critical Citrix NetScaler auth bypass now leveraged in attacks

BleepingComputer

Attackers are now exploiting a significant vulnerability in Citrix NetScaler, identified as CVE-2026-19490, which allows for authentication bypass. This flaw poses a severe risk as it could enable unauthorized access to systems using affected versions of NetScaler. Companies that utilize Citrix NetScaler for application delivery or networking are particularly at risk, as this vulnerability can compromise their security posture. Security researchers from Previdian have reported that the flaw is actively being exploited in the wild, indicating an urgent need for users to assess their systems. Organizations should prioritize applying any available patches or implementing mitigation strategies to protect against potential breaches.

Sep 4, 2026

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News

PostgreSQL has issued updates to fix a serious security vulnerability, tracked as CVE-2026-6471, that has existed for 12 years. This flaw allows users with the REPLICATION attribute to execute arbitrary code as the operating system user running the database server. The vulnerability affects several versions of PostgreSQL, specifically those released before 18.6, 17.11, 16.15, 15.19, and 14.24. The potential for attackers to exploit this flaw poses a significant risk to database security, making it crucial for users to apply the updates promptly. The vulnerability was introduced with the logical decoding feature in PostgreSQL 9.4, highlighting the importance of regularly updating database systems to protect against long-standing vulnerabilities.

Sep 4, 2026