Threat Advisory

mySCADA myPRO Manager Flaws Permit Unauthorized Access and SMS Message Sending

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting mySCADA myPRO Manager versions and Mitigation have been identified in mySCADA myPRO Manager affecting version 2.1 and earlier. These flaws permit unauthenticated remote attackers to bypass authorization and send arbitrary SMS messages. The overall risk/impact is substantial, as organizations deploy this platform worldwide across critical manufacturing, energy, water, and transportation systems.

CVE-2026-73807 (CVSS 9.8 — Critical): The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to this API could exploit the vulnerability, accessing restricted management functions without credentials.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting mySCADA myPRO Manager versions and Mitigation have been identified in mySCADA myPRO Manager affecting version 2.1 and earlier. These flaws permit unauthenticated remote attackers to bypass authorization and send arbitrary SMS messages. The overall risk/impact is substantial, as organizations deploy this platform worldwide across critical manufacturing, energy, water, and transportation systems.

CVE-2026-73807 (CVSS 9.8 — Critical): The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to this API could exploit the vulnerability, accessing restricted management functions without credentials.[emaillocker id="1283"]

CVE-2026-82567 (CVSS 6.3 — Medium): The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. An attacker can send a network request to this endpoint with a message payload.

RECOMMENDATION:

We recommend you to update mySCADA myPRO Manager to version 2.2.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu