That one, yes :)
Their whole analysis is based on this claim: "claiming they could be able to breach the system, change votes and vote totals, and erase any evidence of their actions if they could install malware on the election servers."
That is true for all server based software.
Procedures have been set up to mitigate this risk. All software, servers and anything else running in the network is audited before, during and after the election. The whole process is public and anyone can become an observer, just like with paper ballots. There really are many eyeballs making sure the election servers are running the software they are supposed to.
AFAIK everything else they pointed out was purely procedural and the guidelines there have been updated. There really weren't any reproducible technical issues and some of the procedural ones are outright misrepresentations.
The full sources for these two are sadly in Estonian, but the main response to that research can be seen here in English: http://www.vvk.ee/uudised/vabariigi-valimiskomisjoni-vastula...
"""
Posted Wi-Fi credentials
— The official video
of the pre-election process reveals credentials for the election
officials’ Wi-Fi network, which are posted on the wall.
"""
The credentials were actually just for a separate public guest network, that has nothing to do with the "election officials network" or the network where the voting servers are.
or:
"""
Keystrokes reveal root passwords
— Videos
posted by officials during the election show operators typing,
inadvertently revealing root passwords for election servers.
"""
Although this was recognized as a possible attack vector and the procedures for filming have been updated, the "operator" typing a password was actually one of the observers typing a password in their own computer.
Obviously any hints to compromised processes are taken with 100% seriousness and if needed processes and guidelines are changed to protect the integrity of the system.
Any technical reports are also (publicly) analyzed and if an issue is indeed found, they're fixed. The thing is, "https://estoniaevoting.org" said everything is bad, and the system should not be used, but never published/provided any re-producible test-cases that could be verified.
OSCE has audited all of our elections, they've given some procedural pointers that have been implemented, but OSCE observers have not deemed our elections compromised.
This is their 2011 audit: http://www.osce.org/odihr/77557?download=true, the pointers given to improve our system have been implemented by now.
And here is their 2015 audit: http://www.osce.org/odihr/elections/estonia/160131?download=..., which has some new pointers, but again has not deemed the system to be insecure.
We're having another parlamentary election in 2019 and again, the system will be improved for that(more verification methods are being implemented), but so far, all of our elections have been deemed acceptable and work is being done to keep the track record.