Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Recap

    Medical Device Cybersecurity News: Recent Highlights, Week of Monday, August 24, 2026

    [!WARNING] Devices running RHEL 7 are no longer receiving security patches. Manufacturers must document compensating controls in the postmarket file to address unpatched vulnerabilities.

    Hero image for Medical Device Cybersecurity News: Recent Highlights, Week of Monday, August 24, 2026
    Week of August 24, 2026 · The Goat's Weekly
    On this page

    In this issue

    • FDA & US regulatory

      Letters, guidance, enforcement

    • CISA KEV & CVEs

      Vulnerabilities in your SBOM

    • Standards & international

      AAMI, ISO, IEC, EU MDCG

    • What to do this week

      Concrete actions for security leads

    3 min read691 words

    Key Takeaways

    • RHEL 7 Extended Life Support officially ended on June 30, 2026.
    • Security errata for RHEL 7 are no longer being issued by Red Hat.
    • The FDA expects manufacturers to have documented migration plans for legacy operating systems.
    • Compensating controls must be justified in postmarket files if migration is not feasible.
    • Inventory management of deployed systems is necessary to identify RHEL 7 dependencies.

    The most critical regulatory update for this period is the end of Extended Life Support for RHEL 7, which concluded on June 30, 2026. Device manufacturers must now ensure their postmarket files include either a formal migration plan or a documented compensating controls memo to satisfy the FDA requirements for legacy systems.

    While this week has been relatively quiet, the last 90 days have solidified several key expectations for device manufacturers regarding legacy software and operating system support. As the industry moves further into the second half of 2026, the focus has shifted from initial implementation of cybersecurity controls to the long term maintenance of software bills of materials.

    In this brief

    Why This Matters

    For security and regulatory leads, the end of support for a major operating system represents a direct increase in the attack surface of the installed base. Failing to document how these risks are mitigated can lead to complications during the FDA postmarket reviews or when submitting updates for legacy platforms.

    End of Support for RHEL 7 Extended Life Cycle

    High

    As of June 30, 2026, RHEL 7 reached the end of its Extended Life Support (ELS) period.

    ## What to do this week * Review your current Software Bill of Materials (SBOM) to identify any active medical device product lines still utilizing RHEL 7. * Draft a formal internal memo outlining the specific compensating controls, such as network isolation or restricted user access, for devices that cannot be updated. * Schedule a review with the regulatory affairs team to ensure the postmarket file reflects the current end of support status for these legacy systems.

    How Blue Goat Cyber Helps

    Blue Goat Cyber provides specialized services to help manufacturers navigate legacy software challenges and FDA postmarket requirements. Our team assists in developing compensating control justifications and long term migration strategies to maintain the security posture of your device fleet. You can learn more about our approach at our services page.

    FAQ

    Get the next issue

    To stay informed on the latest medical device cybersecurity updates, subscribe to Goat's Weekly.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.