We use cookies and similar technologies to measure how our site and advertising perform. You can accept or decline. Declining keeps the site fully usable and only turns off measurement. See our privacy policy.

    Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    ⌘K
    Recap

    Medical Device Cybersecurity News: Recent Highlights, Week of Monday, September 21, 2026

    The end of Extended Life Support for RHEL 7 marks a critical milestone for manufacturers maintaining legacy device fleets.

    Hero image for Medical Device Cybersecurity News: Recent Highlights, Week of Monday, September 21, 2026
    Week of September 21, 2026 · The Goat's Weekly
    On this page

    In this issue

    • FDA & US regulatory

      Letters, guidance, enforcement

    • CISA KEV & CVEs

      Vulnerabilities in your SBOM

    • Standards & international

      AAMI, ISO, IEC, EU MDCG

    • What to do this week

      Concrete actions for security leads

    3 min read606 words

    Key Takeaways

    • RHEL 7 Extended Life Support officially ended on June 30, 2026.
    • The FDA expects documented migration plans for devices using unsupported operating systems.
    • Compensating controls must be justified in postmarket files if updates are not feasible.
    • Inventory management is the first step in addressing legacy OS vulnerabilities.
    • Security errata are no longer issued for RHEL 7, increasing the risk of unpatched vulnerabilities.

    The end of Extended Life Support for RHEL 7 marks a critical milestone for manufacturers maintaining legacy device fleets. Regulatory bodies now expect formal documentation regarding compensating controls or migration paths for any devices still utilizing this operating system.

    While this week has been relatively quiet for new regulatory filings, the recent sunsetting of major legacy software support continues to impact postmarket compliance. Manufacturers must shift focus from active development to ensuring their legacy portfolios meet current cybersecurity expectations.

    In this brief

    Why This Matters

    For medical device manufacturers, the end of life for an operating system is not just a technical hurdle but a regulatory one. Failure to account for the lack of security patches in a legacy environment can lead to non-compliance during postmarket reviews and increase the attack surface of the healthcare provider's network.

    Legacy Fleet Management: The RHEL 7 ELS Cut-off

    High

    Red Hat Enterprise Linux (RHEL) 7 reached the end of its Extended Life Support (ELS) phase on June 30, 2026.

    ## What to do this week * Audit your current product portfolio to identify all active or serviced devices still utilizing RHEL 7. * Draft a formal compensating-controls memo for any RHEL 7 devices that cannot be immediately migrated to a newer OS version. * Update your postmarket cybersecurity management plan to reflect the end of support for these legacy components.

    How Blue Goat Cyber Helps

    Blue Goat Cyber assists manufacturers in navigating complex regulatory requirements through specialized services. Our team, led by experts like Christian Espinosa, provides guidance on documenting compensating controls and performing risk assessments for legacy systems. You can learn more about our approach at our services page.

    FAQ

    Get the next issue

    To stay updated on medical device cybersecurity trends, subscribe to Goat's Weekly.

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 275+ FDA submissions.