Team,
This is my new piece pertaining to newly released documents that reveal both how vulnerable some election systems have been and how long the government has known about the threats.
You can also read my piece HERE in the Washington Times.
The documents include a retrospective report from the Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and declassified intelligence records.
The most troubling question may be why Americans are only now getting this consolidated picture. Much of the election systems testing occurred years ago. CISA’s own report says its election-software evaluation program with the Idaho National Laboratory ran from 2019 through 2024, and final reporting on that program concluded in 2025.
Now we have a public CISA report pulling the findings together, including the stunning admission that federal testers sometimes gained full network control within hours or days. Congress should find out why this consolidated public accounting came only now.
Let’s be clear — and clear-eyed. This is a bipartisan issue ripe for action on the Hill.
America’s election infrastructure is a target for anyone who would seek to manipulate or disrupt our elections.
With fewer than 90 days before what may be one of the most consequential congressional elections in our history, Congress should act. The 2026 general election is November 3. The government has already written the prescription, if not the bill.
Stop certification rules from blocking security fixes. If a vulnerability is found in October, election officials should be able to patch it that month — not wait until after the election. CISA itself recommends harmonizing patch-management and certification rules so cybersecurity changes can be made in real time without jeopardizing certification.
Mandate human-readable paper ballots and manual audits of those ballots before results are certified. Require vendors to do what CISA now recommends: Assign CVE (Common Vulnerabilities and Exposures) numbers to vulnerabilities, notify customers if source code is leaked or stolen, report cybersecurity incidents, provide a software bill of materials and transparently document incidents and remediation.
Build the vendor-verification screen requested by the intelligence community in 2020 — and include foreign ownership and control in the review. We scrutinize the companies that build our weapons. We should also scrutinize the companies that build our voting systems.
I look forward to reading your comments. Please share this.
Peter
CISA warnings expose America’s election security gaps
Federal testers found weak networks, delayed patches and voting-system vulnerabilities
By Peter Navarro - Sunday, August 16, 2026
Picture a break-in where the burglars are the good guys.
From 2019 through 2024, federal cybersecurity teams were invited to probe election software and networks. The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) conducted penetration tests and red-team operations against state and local networks, while CISA and the Idaho National Laboratory worked with election vendors to tear into election software.
Their mission was straightforward: Find the weak points before real adversaries could exploit them.
Newly released government documents — including a retrospective CISA report and declassified intelligence records — reveal both how vulnerable some election systems have been and how long the government has known about the threats.
The CISA report reveals that “in multiple cases, CISA assessors gained full network control within hours or days.” Many state and local partners, it warned, “remain soft targets incapable of stopping even moderately skilled adversaries.”
The break-ins were possible for a simple structural reason. Election systems that were supposed to be isolated often were not. Get into an ordinary government office network — the network carrying email and office applications — and in some cases, you could reach election systems.
Translation: The walls that everyone assumes separate election systems from ordinary office computers can be porous. CISA found election systems reachable from enterprise networks, with firewall gaps and supposedly “isolated” equipment quietly still connected.
Worse still, CISA says some election systems are “locked down” against changes for weeks or months before Election Day, and in some cases, those lockdown periods are mandated by state law.
Certification requirements can also delay security updates. CISA does not identify the states. But its warning is explicit: Some certification regimes “require that no patches be applied for months before an election.”
Read that again. In some jurisdictions, rules meant to protect election systems can prevent officials from fixing a known security hole during the very period an adversary has the greatest incentive to exploit it.
The result, according to CISA: “known, documented vulnerabilities persist for months or years” on production election systems.
Then there are the voting machines themselves, the third rail of election-denier politics — the Voldemort words that one dares not speak.
CISA’s new report revives a warning that has been sitting in plain sight for years. A 2021 expert report filed in federal court in Georgia found that ballot-marking devices encoded voters’ choices in barcodes which “voters had no way to verify.”
The researcher demonstrated that those encoded choices could be altered without physical access to the machines. To be precise, the analysis showed that votes could be changed (not that they actually were).
What is striking is that CISA is still citing the vulnerability in 2026 — and still recommending human-readable paper ballots.
And what about who controls the companies that build our voting systems? A newly released January 2020 National Intelligence Council memo proposed a simple safeguard called “Third-Party Vendor Verification” whereby companies that manufacture or transship election infrastructure would be screened for shared vulnerabilities and insider threats.
The concern was not theoretical. A separate CIA review released this summer, drawing on intelligence dating back to 2004, recounts how Smartmatic’s acquisition of U.S. voting-system company Sequoia triggered a 2006 intelligence community national-security assessment.
That assessment rated the acquisition a “moderate” threat to U.S. national-security interests, and the CIA review says subsequent Committee on Foreign Investment in the United States (CFIUS) pressure resulted in Smartmatic divesting Sequoia in 2007.
Let’s be clear — and clear-eyed. This is a bipartisan issue ripe for action on the Hill.
America’s election infrastructure is a target for anyone who would seek to manipulate or disrupt our elections.
With fewer than 90 days before what may be one of the most consequential congressional elections in our history, Congress should act. The 2026 general election is November 3. The government has already written the prescription, if not the bill.
Stop certification rules from blocking security fixes. If a vulnerability is found in October, election officials should be able to patch it that month — not wait until after the election. CISA itself recommends harmonizing patch-management and certification rules so cybersecurity changes can be made in real time without jeopardizing certification.
Mandate human-readable paper ballots and manual audits of those ballots before results are certified. Require vendors to do what CISA now recommends: Assign CVE numbers to vulnerabilities, notify customers if source code is leaked or stolen, report cybersecurity incidents, provide a software bill of materials and transparently document incidents and remediation.
Build the vendor-verification screen requested by the intelligence community in 2020 — and include foreign ownership and control in the review. We scrutinize the companies that build our weapons. We should also scrutinize the companies that build our voting systems.
The most troubling question may be why Americans are only now getting this consolidated picture. Much of the testing occurred years ago. CISA’s own report says its election-software evaluation program with the Idaho National Laboratory ran from 2019 through 2024, and final reporting on that program concluded in 2025.
Now we have a public CISA report pulling the findings together, including the stunning admission that federal testers sometimes gained full network control within hours or days. Congress should find out why this consolidated public accounting came only now.
• Peter Navarro is assistant to the president and senior counselor for trade and manufacturing. www.peternavarro.com



Given the facts and the Democrats' uniform opposition to cleaning up the mess, one can only conclude that Democrats are in favor of crooked elections.
Analysis of the EssayThe author makes a compelling, national-security-focused case for updating federal standards surrounding election software security and vendor supply chains.Key Strengths of the Author's Argument:Bipartisan Framing: Framing cybersecurity as an ongoing, defense-level priority rather than a partisan topic makes actionable policy more achievable.Streamlined Security Patching: Identifying the friction between state certification rules and emergency zero-day vulnerability patching is a critical operational insight.Vendor Transparency: Demanding a Software Bill of Materials (SBOM), CVE assignment, and supply chain scrutiny mirrors security standards applied to the Department of Defense.Additional Recommendations to Enhance US Election IntegrityTo complement and expand upon the author's proposals, Congress, the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Election Assistance Commission (EAC) should consider five additional structural enhancements:1. Implement Standardized Risk-Limiting Audits (RLAs)Beyond Basic Audits: While the author rightly advocates for hand-counted paper ballots, basic manual audits can be inefficient or statistically weak if sample sizes are arbitrary.The Upgrade: Mandate Risk-Limiting Audits (RLAs) nationwide prior to certification. RLAs use statistical sampling of paper ballots to provide a mathematically verifiable level of confidence that the reported election outcome matches the paper record, maximizing scrutiny where margins are tight while saving local election staff time.2. Establish a Fast-Track Federal Security Patching ProtocolThe Problem: State-level recertification requirements can take 6–12 months, leaving systems exposed to publicly known exploits.The Upgrade: Create an emergency "Trusted Patch Architecture" through the EAC. Under this framework, security-only micro-patches that do not alter voting logic can be pre-approved by accredited labs within 72 hours, allowing state officials to apply security updates without invalidating overall system certification.3. Formalize Mandatory Incident Disclosure TimelinesThe Upgrade: Require election vendors and jurisdiction IT administrators to notify CISA and state chief election officials within 24 hours of confirming any breach, unauthorized access, or credential leak involving voting infrastructure, under penalty of losing federal certification.4. Mandate Air-Gapped Physical Architecture & Chain of CustodyThe Upgrade: Pass explicit federal standards prohibiting tabulation hardware from containing wireless networking chips (including dormant Wi-Fi or cellular modems) on primary circuit boards. Require tamper-evident physical seals and dual-custody access protocols for all voting equipment storage facilities to mitigate insider threat risks.5. De-escalate Supply Chain Foreign Dependency via National Defense FundingThe Upgrade: Classify voting machine hardware manufacturing under critical national defense infrastructure. Provide targeted grants via the Defense Production Act to ensure circuit boards, touchscreens, and optical sensors are manufactured, assembled, and vetted entirely within trusted, domestically audited facilities.Official Election & Voting ResourcesFor official guidance on voting rules, state-by-state mail-in deadlines, polling place locators, and election administration standards, refer directly to official government portals:Verify Voter Registration & Polling Places: Check your status or find local voting centers via Can I Vote (National Association of Secretaries of State) or your state's Secretary of State portal.Federal Election Infrastructure Guidelines: Review official security standards, physical security checklists, and incident reporting guidance at the CISA Election Security Resource Library. Voting System Testing & Certification: Access certification reports, audit tools, and clearinghouse standards at the U.S. Election Assistance Commission.