TL;DR
CISA disclosed two severe mySCADA myPRO Manager vulnerabilities affecting version 2.1 and earlier. These flaws permit unauthenticated remote attackers to bypass authorization and send arbitrary SMS messages. Administrators must update to version 2.2 immediately to secure their industrial control environments.
- Product: mySCADA Technologies mySCADA myPRO
- Vulnerabilities: 2 flaws (CVE-2026-73807, CVE-2026-82567)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Manager Missing Authorization
- Status: No confirmed exploitation yet; patches available
- Action: Update to 2.2 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-73807 | 9.8 | Manager Missing Authorization | 2.2 | Not exploited |
| CVE-2026-82567 | 6.3 | Manager Missing Authorization | 2.2 | Not exploited |
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
Organizations deploy mySCADA myPRO Manager worldwide across critical manufacturing, energy, water, and transportation systems. Consequently, vulnerabilities within this platform pose a substantial threat to essential industrial operations. If an attacker exploits these mySCADA myPRO Manager vulnerabilities, they can access privileged management functions. This access could allow threat actors to disrupt critical infrastructure or manipulate industrial processes. They could also use the connected GSM modem to launch secondary attacks.
How the Attack Works
The most severe flaw, CVE-2026-73807, involves missing authorization within the command API. According to the advisory, “The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions.” An unauthenticated attacker with network access to this API could exploit the vulnerability. This allows them to access restricted management functions without credentials.
The second vulnerability, CVE-2026-82567, involves a missing authentication check in the notification gateway. The advisory notes, “The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem.” An attacker can send a network request to this endpoint with a message payload.
CISA confirmed that no active exploitation or public proof-of-concept currently targets these vulnerabilities.
Affected Versions and Mitigation
These vulnerabilities affect all mySCADA myPRO Manager installations running version 2.1 and earlier. mySCADA Technologies has resolved these security defects in version 2.2. Administrators should upgrade their systems to the latest version immediately. If direct updates are delayed, defenders should isolate control system networks behind firewalls.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!