← Back to Feed

mySCADA myPRO Manager

CVE-2026-73807CVE-2026-82567

September 15, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected: mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567) CVSS Vendor Equipment Vulnerabilities v3 9.8 mySCADA Technologies mySCADA myPRO Manager Missing Authorization, Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Czechia Vulnerabilities Expand All + CVE-2026-73807 The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions. View CVE Details Affected Products mySCADA myPRO Manager Vendor:mySCADA Technologies Product Version:mySCADA Technologies mySCADA myPRO Manager: <=2.1 Product Status:known_affected Remediations MitigationmySCADA Technologies has addressed these issues in Version 2.2 and recommends that users update to the latest version. Users are notified in mySCADA Pro Manager about the availability of a new version if the device is connected to the internet. Otherwise, users can download the mySCADA Pro Manager from the webpage.https://www.myscada.org/downloads/mySCADAPROManager/ Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-82567 The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a...

Key Takeaways

  • mySCADA myPRO Manager vulnerabilities could allow attackers to access privileged management functions or send arbitrary SMS messages through connected GSM modems.
  • Exploitation of these flaws could disrupt industrial control operations by manipulating SMS-based alerts and commands used in remote monitoring scenarios.
  • Operators of mySCADA myPRO systems should prioritize patching due to the potential for physical-world impact from compromised industrial control interfaces.
☕ Buy a Coffee