IM
IronMonkey Threat Research
‹ Back to ICS Advisories

mySCADA myPRO Manager

CRITICAL
CVSS 9.8
Date 2026-09-15T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-73807 9.8 critical
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
CVE-2026-82567 6.3 medium
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem.

// Affected Products (1)

Vendor Product Asset Type Purdue Level Firmware
mySCADA Technologies Unknown scada_server
L2
--

// Remediations (1)

Mitigation: mySCADA Technologies has addressed these issues in Version 2.2 and recommends that users update to t
mySCADA Technologies has addressed these issues in Version 2.2 and recommends that users update to the latest version. Users are notified in mySCADA Pro Manager about the availability of a new version if the device is connected to the internet. Otherwise, users can download the mySCADA Pro Manager from the webpage.

// References