On this page
In this issue
-
FDA & US regulatory
Letters, guidance, enforcement
-
CISA KEV & CVEs
Vulnerabilities in your SBOM
-
Standards & international
AAMI, ISO, IEC, EU MDCG
-
What to do this week
Concrete actions for security leads
Key Takeaways
- RHEL 7 Extended Life Support has officially ended, mandating new compensating controls for legacy fleets.
- CISA added a Linux kernel netfilter use-after-free (CVE-2026-0511) to the KEV catalog.
- A widely embedded Bluetooth Low Energy (BLE) pairing bypass is now listed as a known exploited vulnerability.
- Federal remediation timelines are now active for devices utilizing these affected components.
- The FDA expects documented migration plans or justifications for any devices still running unsupported software versions.
The recent addition of multiple embedded vulnerabilities to the CISA Known Exploited Vulnerabilities catalog signals a shift in federal expectations for medical device remediation. Manufacturers must now account for active exploits in Linux kernels and Bluetooth stacks while managing the end-of-life transition for legacy operating systems like RHEL 7.
This week we are reviewing significant regulatory and security updates from the past quarter. While recent days have been quiet, the accumulation of new entries in the CISA Known Exploited Vulnerabilities (KEV) catalog and the expiration of legacy support for common enterprise Linux distributions create a complex landscape for postmarket surveillance.
Security leads and regulatory officers should use this period to reconcile their Software Bill of Materials (SBOM) against these new threats. Addressing these items now ensures that future submissions to the FDA do not face delays due to unaddressed, publicly exploited vulnerabilities.
In this brief
- Expiration of Red Hat Enterprise Linux 7 Extended Life Support
- CISA Adds Linux Kernel Netfilter Vulnerability to KEV
- Embedded Bluetooth Pairing Bypass Vulnerability
- What to do this week
- How Blue Goat Cyber Helps
- FAQ
Why This Matters
For medical device manufacturers, a KEV listing changes the risk calculation from theoretical to demonstrated. The FDA and healthcare delivery organizations increasingly use the KEV catalog to prioritize patches. Failure to address these known exploits or provide a clear path forward for legacy systems can stall regulatory clearances and impact hospital procurement decisions.
Red Hat Enterprise Linux 7 Extended Life Support Ends
As of June 30, 2026, RHEL 7 Extended Life Support (ELS) has reached its final end of support date.
Linux Kernel Netfilter Vulnerability Added to KEV
CISA recently added CVE-2026-0511, a use-after-free vulnerability in the Linux kernel netfilter component, to the KEV catalog.
Bluetooth Low Energy Pairing Bypass Added to KEV
A Bluetooth Low Energy (BLE) pairing bypass vulnerability has been added to the KEV catalog.
How Blue Goat Cyber Helps
Blue Goat Cyber assists medical device manufacturers in navigating these regulatory hurdles through technical testing and strategic compliance support. Our team, led by Christian Espinosa, helps bridge the gap between cybersecurity engineering and FDA requirements. Whether you need an update to your regulatory tracker status or assistance with postmarket files, we provide targeted expertise.
FAQ
Get the next issue
Subscribe to stay updated on the latest medical device security trends at /news/the-goats-weekly.
