The Cybersecurity and Infrastructure Security Agency (CISA) has released a comprehensive assessment detailing persistent vulnerabilities and systemic challenges within U.S. election infrastructure, following a series of technical evaluations conducted between 2019 and 2024.
The report, dated July 13, 2026, compiles data from direct software examinations, network penetration testing, and incident response operations conducted at the request of state, local, tribal, and territorial (SLTT) entities.
According to the federal agency, while election-related software contains security flaws common to all complex software, the ability to fix these flaws is severely restricted by current regulatory frameworks. CISA noted that structural constraints within the government certification ecosystem significantly limit how quickly private vendors can patch their products.
In many jurisdictions, state laws or federal guidelines mandate “lockdown” periods that prevent any software changes for weeks or months leading up to an election. The report states that these limitations, “combined with inconsistent vulnerability disclosure practices, result in election systems being deployed with known and unpatched security issues.”
The assessment also highlighted widespread cybersecurity weaknesses in the local networks that host these voting systems. While election software vendors design their threat models under the assumption that election systems will be strictly isolated from the rest of a government’s IT network, CISA’s real-world testing revealed a different reality.
Assessors frequently found flat or minimally segmented networks, which allowed them to gain full network control within days by moving laterally from standard corporate assets, such as compromised user workstations or email accounts, into mission-critical election components. CISA attributed these vulnerabilities to weak identity management, a lack of multi-factor authentication enforcement, and insufficient network traffic monitoring.
The report traced these systemic risks to three primary interacting factors: software patch management constrained by outdated certification regimes, a lack of consistent transparency from election vendors regarding known software bugs, and the cybersecurity immaturity of many local government networks.
CISA previously attempted to address software security prior to market release through its Critical Product Evaluation program in partnership with Idaho National Laboratory. However, the agency retired the program in 2024 after finding that it incentivized private remediation rather than industry-standard public disclosure, leaving downstream risk managers and local administrators without clear vulnerability histories.
The security findings also extended to physical hardware. CISA noted that while most jurisdictions have shifted away from paperless electronic voting machines to ensure a physical trail, the newer paper-based systems are not immune to technical risks.
The report cited a 2021 expert analysis of 2020 ballot-marking devices that printed voter selections as unreadable barcodes, which researchers demonstrated could theoretically be manipulated by bad actors.
CISA also acknowledged reviewing a 2025 forensic report commissioned by the Office of the Director of National Intelligence regarding Dominion Voting Systems devices utilized in Puerto Rico’s 2024 election, though CISA personnel did not have physical access to the devices to conduct an independent examination.
To mitigate these overlapping risks, CISA outlined several technical and policy recommendations. Chief among them is the modernization of certification rules to allow election officials to apply critical security patches in real-time without voiding their official certification status.
The agency also urged the universal adoption of human-readable paper ballots, regular manual post-election audits to verify machine counts before results are certified, and stricter requirements for software vendors.
Specifically, CISA recommended that vendors assign formal Common Vulnerabilities and Exposure (CVE) numbers to software bugs, immediately notify clients if source code is compromised, and provide a comprehensive Software Bill of Materials (SBOM) with all products to ensure long-term supply chain transparency.
READ: DHS Finds Over 250,000 Non-Citizen Voter Registrations Across Four States
Please make a small donation to the Tampa Free Press to help sustain independent journalism. Your contribution enables us to continue delivering high-quality, local, and national news coverage.
Sign up: Subscribe to our free newsletter for a curated selection of top stories delivered straight to your inbox.

