VYPR
advisoryPublished Sep 15, 2026· 1 source

Critical Vulnerabilities in mySCADA myPRO Manager Allow Unauthenticated Access and SMS Spoofing

CISA has disclosed two critical vulnerabilities in mySCADA myPRO Manager, versions prior to 2.1, enabling unauthenticated attackers to access privileged functions or send arbitrary SMS messages.

CISA has issued a warning regarding two critical vulnerabilities affecting mySCADA myPRO Manager software, specifically versions prior to 2.1. These flaws, identified as CVE-2026-73807 and CVE-2026-82567, could allow unauthenticated attackers to gain unauthorized access to sensitive management functions or to send arbitrary SMS messages through a connected GSM modem.

The first vulnerability, CVE-2026-73807, is a missing authorization flaw within the mySCADA myPRO Manager's command API. This means that an attacker who can reach the API over a network, without needing any credentials, can exploit this weakness to access privileged management functions. The potential impact includes unauthorized configuration changes, system control, or data exfiltration, depending on the specific privileges associated with these functions.

Compounding the risk, CVE-2026-82567 is a missing authentication vulnerability in the myPRO Manager's notification gateway. This component exposes an HTTP endpoint that allows for sending SMS messages via a connected GSM modem. Crucially, this endpoint does not require any form of authentication, enabling an unauthenticated attacker with network access to send any SMS message they choose through the compromised device.

These vulnerabilities carry significant implications for various critical infrastructure sectors, including Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, and Water and Wastewater. The worldwide deployment of mySCADA myPRO Manager means that organizations across numerous countries could be at risk. The vulnerabilities have been assigned high CVSS scores, with CVE-2026-73807 rated as CRITICAL with a base score of 9.8 (CVSS:3.1) and 9.3 (CVSS:4.0), while CVE-2026-82567 is rated MEDIUM with a base score of 6.3 (CVSS:3.1) and 5.3 (CVSS:4.0).

mySCADA Technologies has responded to these findings by releasing version 2.2 of myPRO Manager, which addresses both vulnerabilities. The company recommends that all users update to the latest version as soon as possible. For devices connected to the internet, the software will notify users of the new version's availability. Otherwise, users can manually download the update from the mySCADA website.

CISA strongly advises organizations to implement defensive measures to mitigate the risk of exploitation. These recommendations include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls. When remote access is necessary, secure methods such as VPNs should be employed, with the understanding that VPNs themselves require regular updates and secure configurations.

While no public exploitation of these specific vulnerabilities has been reported to CISA at this time, the critical nature and high CVSS scores warrant immediate attention. The combination of unauthorized access to management functions and the ability to send arbitrary SMS messages presents a potent threat vector for attackers seeking to disrupt operations or conduct further malicious activities within industrial environments.

Shirshak Secnora OÜ is credited with reporting these vulnerabilities to CISA. Organizations are encouraged to follow CISA's guidance on ICS cybersecurity best practices and to report any suspected malicious activity for correlation with ongoing threat intelligence.

Synthesized by Vypr AI