CISA Election Security Plan Highlights Patching Hurdles and Voter Database Threats
CISA's 2026 Election Infrastructure Security Plan identifies critical vulnerabilities in election systems, including challenges with patching and the persistent threat of attacks targeting voter databases.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has unveiled its comprehensive 2026 Election Infrastructure Security Plan, detailing the cyber and physical threats that election systems face and outlining the free services CISA provides to election officials and partners. This plan, initiated in July by Homeland Security Secretary Markwayne Mullin, acknowledges that while state and local election officials bear the primary responsibility for safeguarding election infrastructure across thousands of jurisdictions, the federal government, through CISA, offers crucial information, tools, and resources to bolster these defenses.
A significant concern highlighted in the plan is the "structural constraints within the certification ecosystem" that impede timely patching of election software vulnerabilities. These constraints can prevent vendors from releasing necessary security updates and hinder system owners from applying them promptly. Compounding this issue, CISA's assessments reveal that many state, local, tribal, and territorial (SLTT) election offices struggle with fundamental cyber hygiene and vulnerability remediation. Furthermore, election infrastructure often lacks proper network segmentation, being accessible from general enterprise networks, which allows attackers who compromise less secure systems like email or workstations to move laterally into critical election systems.
The agency pinpoints three core issues contributing to this vulnerability management gap: outdated certification regimes that conflict with modern patch management practices, a lack of consistent vendor transparency regarding vulnerabilities and patch status, and the general cybersecurity immaturity observed across many SLTT networks hosting election systems. To address these challenges, CISA recommends aligning patch management processes with certification requirements to enable real-time security updates without compromising system certification. The plan also advocates for the continued use of paper ballots and manual post-election audits as essential safeguards.
CISA further urges election officials to encourage software providers to adopt more robust security practices. This includes assigning CVE identifiers to disclosed flaws, promptly informing customers about any source code leaks or theft, reporting security incidents to relevant authorities, and providing a software bill of materials (SBOM) with every product. These measures aim to increase transparency and accountability within the election technology supply chain, empowering officials to better understand and mitigate risks associated with the software they deploy.
Voter registration databases remain a prime target for foreign adversaries, as evidenced by reports over the past decade. CISA notes that hackers have attempted to breach these systems in all 50 states, with confirmed successes in at least 20 states. To fortify these critical databases, the plan prioritizes the implementation of multi-factor authentication, continuous network monitoring for anomalies, strict access controls based on the principle of least privilege, and the retention of critical logs for at least one year. Additionally, it stresses the importance of isolating public-facing online registration and lookup tools from the master databases.
Insider risks, encompassing permanent staff, temporary workers, volunteers, contractors, and vendors, are identified as a growing concern. Seasonal and volunteer personnel may not undergo the same rigorous vetting as permanent staff, potentially creating vulnerabilities. Malicious insiders could intentionally alter voter registration data, ballot definitions, or tabulation settings, while careless insiders might fall victim to phishing attacks, connect unauthorized removable media, or mishandle equipment. CISA suggests formalizing existing practices like bipartisan ballot handling and chain-of-custody procedures into documented insider threat programs to mitigate these risks.
Beyond cyber threats, CISA also addressed physical security, noting that bomb threats constituted the majority of election-related security incidents tracked through open-source reporting since January 2022. For the upcoming 2026 election cycle, CISA is facilitating a no-cost information-sharing platform for all fusion centers and state and local election officials, enabling near real-time communication with peers and federal partners—a model successfully deployed during the FIFA World Cup 2026. The plan also reiterates the availability of free CISA services, including vulnerability scanning, penetration testing, risk assessments, and decoy systems, to help election offices enhance their security posture.