CISA Releases Advisory on Flaws in Dominion Voting Machines; Director Jen Easterly Quoted

CISA Releases Advisory on Flaws in Dominion Voting Machines; Director Jen Easterly Quoted

The Cybersecurity and Infrastructure Security Agency has issued an advisory saying it found no evidence that vulnerabilities in Dominion in-person voting systems were exploited in any elections, CBS News reported Friday.

According to the advisory, CISA identified nine vulnerabilities in certain versions of Dominion Voting Systems ImageCast X software, including improper verification of cryptographic signatures, authentication bypass by spoofing, incorrect privilege assignment and origin validation error.

The agency said exploitation of these flaws would require physical access to ImageCast X devices, capability to alter files before they are uploaded to such devices or access to the Election Management Systems.

Over the past week, we've been working with election officials on information regarding vulnerabilities affecting certain versions of Dominion Voting Systems' software,” CISA Director Jen Easterly, a 2022 Wash100 Award winner, said in a statement Friday. "Today, we are releasing this information publicly." 

CISA recommends several measures election officials should take to prevent the exploitation of these vulnerabilities.

These include reaching out to Domain Voting Systems to determine which software updates need to be implemented; ensuring all affected devices are physically protected before, during and after voting; closing any background application windows on each ImageCast X device; disabling the “Unify Tabulator Security Keys” feature on the EMS and ensuring new cryptographic keys are used for each election; and conducting rigorous post-election tabulation audits.

Many of these mitigations, which are typically standard practice in jurisdictions where these devices are in use, are able to detect exploitation of these vulnerabilities and in many cases would prevent attempts entirely if diligently applied, making it very unlikely that a malicious actor could exploit these vulnerabilities to affect an election,” added Easterly. 

Share the Post:

Related Posts

2026 Wash100 Popular Vote Week 6: Guetlein, Driscoll Among Biggest Climbers, Frazer of PTS Debuts

The sixth week of voting in the 2026 Wash100 popular vote competition brought another round of rising totals and notable upward movement across the leaderboard. Several contenders gained ground compared...

Agile Defense CEO Rick Wagner Accepts 7th Wash100 Award From Executive Mosaic

Rick Wagner, CEO of Agile Defense, has received the 2026 Wash100 Award in recognition of his continued influence across the GovCon sector and the decisive leadership he has demonstrated since...

ITC Federal CEO Greg Fitzgerald Accepts 2026 Wash100 Award

Greg Fitzgerald, CEO of ITC Federal, has accepted the 2026 Wash100 Award in recognition of his leadership in expanding the company’s federal market presence and advancing IT transformation to support...