Critical Vulnerabilities Render Certified U.S. Election Systems Insecure

Issued By: Mark Cook
Cybersecurity Professional, 40+ Years Experience
Date: May 13, 2026

I am issuing this formal security advisory to notify all state election officials, the U.S. Election Assistance Commission, federal agencies, and the American public that multiple certified voting systems currently in use across the United States are critically vulnerable to publicly available exploits.

A single independent security researcher operating under the name Nightmare-Eclipse has publicly released four powerful exploits: RedSunBlueHammerUnDefend, and YellowKey. These exploits target multiple critical components of the Windows operating system.

Detailed Breakdown of the Exploits:

The fact that these severe vulnerabilities were only recently discovered does not mean they have not been exploited for years. Zero-day vulnerabilities of this nature can remain undetected for long periods before being publicly disclosed.

Recognition by the Cybersecurity Community

These exploits have already gained significant attention in the professional cybersecurity community. Leading security firms Huntress and Vectra AI have both published detailed analyses of BlueHammerRedSun, and UnDefend. Huntress has further confirmed they observed these exact tools being used in real-world enterprise intrusions.

The YellowKey BitLocker bypass is much more recent and has not yet received the same level of formal analysis from major firms.

The fact that respected cybersecurity organizations have validated these exploits — and that some have already been used in real attacks — demonstrates that these are not theoretical or exaggerated claims.

Confirmed Vulnerable Certified Systems and Their Exposure:

ES&S (Election Systems & Software)

Dominion Voting Systems

Robis Elections

VR Systems

Clear Ballot Group

These systems passed federal and state certification testing despite containing these critical, exploitable flaws. This demonstrates that the current testing and certification process is fundamentally inadequate.

A Message to Election Officials:

Election officials are being placed in an impossible and unfair position. You are being held legally and professionally responsible for securing and conducting elections using complex computerized systems that you have neither the technical knowledge, expertise, nor resources to properly evaluate or protect.

You are being set up for failure.

Your sworn duty is to protect the integrity of elections for the citizens you serve. These systems make it nearly impossible for you to fulfill that duty. The only responsible course of action is to demand the immediate removal of these vulnerable systems.

Formal Demand:

I formally demand the immediate decertification of all Windows-based voting systems listed in this advisory. The United States must immediately return to transparent, observable elections using hand-counted paper ballots, paper poll books, and precinct-level counting on election night as detailed at handcountroadshow.org/solution.

This advisory is released publicly and may be freely distributed by any U.S. citizen or election official.

Mark Cook
Cybersecurity Professional (40+ years)

References:

Primary Exploit Sources (Nightmare-Eclipse)

Major Cybersecurity Company Analyses

Major Media & Security News Coverage

Voting System & Vendor Documentation

Additional Technical Coverage

CALL TO ACTION – What You Need To Do Right Now

This is a national security emergency. Here’s exactly what you must do:

  1. Download the full “Open Formal Security Advisory” from above.
  2. Send via Certified Mail (highest legal impact):
    • Your Secretary of State
    • Your County Election Director or Clerk
  3. Also send the advisory to these federal agencies:
    • U.S. Election Assistance Commission (EAC)
      Email: Use the contact form at (https://www.eac.gov/contactuseac)
      Mail: U.S. Election Assistance Commission, 633 3rd Street NW, Suite 200, Washington, DC 20001
    • CISA (Cybersecurity & Infrastructure Security Agency)
      Email: [email protected]
  4. Include this exact statement in your cover letter or email:
    “This letter constitutes formal legal notice. I am officially notifying you in your official capacity of these critical security vulnerabilities in certified voting systems. You are now on notice of these known exploits. I demand the immediate decertification of all affected systems.”
  5. Document your action — Take a photo of your signed letter and addressed envelope before mailing, and take screenshots of your emails.

image_pdfimage_print
×