From ~2019 to 2024, CISA conducted technical and operational activities to evaluate certain US election systems, all upon request of system owners/operators, including software examination, penetration testing of SLTT (state, local, tribal, and territorial) networks, and incident response for election-system intrusions (p.1).
p.1Election Report (CISA)
Key Insights
AI-generated from the sourced claims — verify against the documents.
Structural constraints in the certification ecosystem limit vendors' ability to patch quickly; some certification regimes require that no patches be applied for months before an election, so systems are deployed with known, unpatched issues.
In multiple cases CISA assessors gained full network control within hours or days, showing many SLTT partners remain 'soft targets'.
Vendor threat models assume strong segmentation between election systems and enterprise IT, but 2019-2024 assessments showed election systems reachable from enterprise hosts via shared auth domains, legacy VLANs, or 'temporary' exceptions; poor firewall hygiene; co-location on general-purpose virtualization clusters; and unreliable 'airgap' assumptions.
The Critical Product Evaluation program created disincentives for transparent, industry-standard vulnerability disclosure; it was retired in 2024 based on stakeholder feedback.
In 2020, ImageCast X Ballot Marking Devices printed ballots encoding selections in a barcode voters could not verify, and a researcher showed hackers could change the barcode-encoded votes without physical machine access.
22 sourced claims
CISA notified the owner/operator in every case it identified a vulnerability in a product or network and encouraged mitigation (p.1).
p.1Structural constraints in the certification ecosystem limit vendors' ability to patch quickly; some certification regimes require that no patches be applied for months before an election, so systems are deployed with known, unpatched issues (p.1).
p.1SLTT election-office IT networks frequently lack cybersecurity hygiene; election infrastructure is often accessible from general enterprise networks, enabling lateral movement by adversaries who compromise email, workstations, or other IT assets (p.1).
p.1US election security is shaped by three factors: (1) software vulnerability management constrained by outdated certification regimes; (2) inconsistent vendor transparency on vulnerabilities and patch status; (3) cybersecurity immaturity of many SLTT networks (p.1).
p.1From 2019-2024 CISA partnered with Idaho National Laboratory (INL) on the Critical Product Evaluation program for direct technical assessments of election software, often before public release, upon vendor request (p.2).
p.2Assessment methods included static source-code review, binary fuzzing of parsers/media handling/data import modules, cryptographic implementation analysis (PRNG misuse, poor key handling), interface/authentication/authorization/API testing, supply-chain dependency reviews, and dynamic analysis in adversarial runtime environments (p.2).
p.2The Critical Product Evaluation program created disincentives for transparent, industry-standard vulnerability disclosure; it was retired in 2024 based on stakeholder feedback, with final reporting concluding in 2025 (p.3).
p.3Vulnerabilities found included input-validation bugs, insecure deserialization, insufficient logging, race conditions, insecure crypto primitives, and privilege-escalation paths; CISA did not independently validate whether production builds in SLTT environments incorporated all fixes (p.3).
p.3SLTT officials face update difficulties due to minimal IT budgets/staff, short deployment windows, and "lockdown" periods (sometimes mandated by state law) barring changes before election day; state laws may require only EAC (Election Assistance Commission)-certified software, delaying updates that postdate certification (p.3).
p.3Technical risks: vendors cannot ship fixes outside narrow certification cycles without jeopardizing eligibility; third-party components (OS, drivers, middleware, crypto libraries) cannot be patched at modern cadence; legacy OS baselines accumulate unpatched vulnerabilities; absence of secure auto-update prevents rapid zero-day response (p.3).
p.3CISA recommends national policymakers encourage harmonization of patch-management and certification rules (p.4).
p.4Across penetration tests and red-team engagements, CISA observed flat/minimally segmented networks, weak identity and access management (poor MFA, shared credentials, weak service-account hygiene), lack of endpoint hardening, legacy remote-access/file-transfer pathways, and insufficient traffic monitoring (p.4).
p.4In multiple cases CISA assessors gained full network control within hours or days, showing many SLTT partners remain "soft targets" (p.4).
p.4Most states have moved away from paperless electronic voting machines; in 2020, ImageCast X Ballot Marking Devices printed ballots encoding selections in a barcode voters could not verify, and a researcher showed hackers could change the barcode-encoded votes without physical machine access (p.4).
p.4Citation given: J. Alex Halderman, Security Analysis of Georgia's ImageCast X Ballot Marking Devices, expert report in Curling v. Raffensperger (Civil Action No. 1:17-CV-2989-AT, N.D. Ga.), with Drew Springall, July 1, 2021 (p.4).
p.4ODNI commissioned a forensic examination of Dominion Voting Systems devices used in Puerto Rico's 2024 election; CISA reviewed the report but did not have access to the devices and could not perform its own examination (p.4).
p.4Citation given: Dominion Voting Systems Democracy Suite Preliminary Vulnerability Assessment, Mojave Research for the ODNI, September 25, 2025 (p.4).
p.4Vendor threat models assume strong segmentation between election systems (voter-registration databases, e-pollbooks, election management/tabulation systems, central scanning) and enterprise IT, but 2019-2024 assessments showed election systems reachable from enterprise hosts via shared auth domains, legacy VLANs, or "temporary" exceptions; poor firewall hygiene; co-location on general-purpose virtualization clusters; and unreliable "airgap" assumptions (vendor support tunnels, remote-management tools) (p.5).
p.5CISA recommended mitigations: harmonize patch/certification rules; adhere to CISA Best Practices for Securing Election Systems; use human-readable paper ballots; conduct post-election manual audits of paper ballots before certification (p.5-6).
p.5Additional recommendations: encourage vendors to assign CVE numbers, notify customers if source code is leaked/stolen, report incidents to authorities, include a software bill of materials (SBOM); and ensure transparent documentation of all security incidents and remediation (p.6).
p.6Conclusion: US election-system security issues stem from complex interdependencies between vendors, certifiers, policymakers, and resource-constrained SLTT partners, not any single entity (p.6).
p.6Reporting at the time
External context — third-party coverage published around these events, linked for reference. Separate from the primary documents.
Page evidence
Election Report (CISA) · p.4

Page OCR text
ELECTION REPORT National policymakers should encourage harmonization of rules applicable to patch management and certification of election systems. Such harmonization would allow SLTT election officials greater flexibility in installing security updates in a timely manner and would present a less fragmented environment for election system vendors. Election Systems in SLTT Operating Environments SLTT Network Security Posture Election software is deployed into SLTT managed networks that frequently lack the defensive maturity assumed in vendor threat models. Across numerous penetration tests and red team engagements, CISA observed recurring structural weaknesses in SLTT-managed networks: e Flat or minimally segmented networks, allowing lateral movement from standard enterprise zones (email servers, line-of-business applications) into election related environments. e Weak identity and access management, including poor enforcement of multi-factor authentication, shared credentials, and inadequate service account hygiene. e Lack of endpoint hardening, including outdated OS versions, insufficient event logging, and unmonitored administrative interfaces. e Legacy remote access and file transfer pathways that remain reachable from segments that should be isolated. e Insufficient monitoring of network traffic, preventing detection of adversary activity. In multiple cases, CISA assessors gained full network control within hours or days, demonstrating that many SLTT partners remain soft targets incapable of stopping even moderately skilled adversaries. Most states have moved away from paperless electronic voting machines, because these systems don’t provide a physical record or give voters a way to ensure their selections were recorded accurately. The replacement paper-voting systems also contain vulnerable components; in 2020, ImageCast X Ballot Marking Devices printed voters’ completed ballots on paper but encoded their selections in a barcode that voters had no way to verify. A researcher showed that hackers could change the votes encoded in the barcode, without even having physical access to the machines.2 The Office of the Director of National Intelligence (ODNI) additionally commissioned a forensic examination of Dominion Voting Systems devices used in Puerto Rico’s 2024 election.* While CISA did review the report, the agency did not have access to those devices and was unable to perform an examination. 1 Cybersecurity and Infrastructure Security Agency (CISA). Cyber Risk Summary: Election Infrastructure (El) Subsector, October 2022- September 2023. Published February 2024. 2 J. Alex Halderman, Security Analysis of Georgia’s ImageCast X Ballot Marking Devices: Expert Report Submitted on Behalf of Plaintiffs Donna Curling, et al., Curling v. Raffensperger, Civil Action No. 1:17-CV-2989-AT, U.S. District Court for the Northern District of Georgia, Atlanta Division, with assistance from Drew Springall, July 1, 2021. 3 Dominion Voting Systems Democracy Suite Preliminary Vulnerability Assessment, Mojave Research for the ODNI, September 25, 2025. 4 Px 1,83 cisa.gov Wa central@cisa.dhs.gov X @CISAgov | @CISACyber ‘in) £) @cisagov As of July 13, 2026 v