HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Authentication Bypass in mySCADA myPRO Manager (CVE-2026-73807, CVE-2026-82567) Threatens OT Management

Two critical authentication flaws in mySCADA myPRO Manager (≤ 2.1) allow unauthenticated attackers to execute privileged functions and send arbitrary SMS messages. The vendor has issued a patch (v2.2); organizations must verify remediation to maintain audit‑ready access‑control evidence.

Verisq™ Intelligence · 📅 September 15, 2026 · 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Critical Authentication Bypass in mySCADA myPRO Manager (CVE‑2026‑73807, CVE‑2026‑82567) Threatens OT Management

What It Is – Two authentication‑related flaws in mySCADA myPRO Manager (≤ 2.1) allow an unauthenticated network attacker to invoke privileged management commands and to send arbitrary SMS messages via the attached GSM modem.

Exploitability – Both CVEs carry a CVSS v3 base score of 9.8 (Critical). Public proof‑of‑concept code has been observed, and the vendor confirms active exploitation in the wild.

Affected Products – mySCADA myPRO Manager ≤ 2.1, produced by mySCADA Technologies (global deployments in critical manufacturing, energy, food & agriculture, transportation, water & wastewater).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous verification of access‑control enforcement on OT management interfaces – a core control objective that maps to multiple frameworks (e.g., NIST CSF Identify and Protect).
  • Provides auditors with concrete evidence of defensible remediation (patch status, version inventory) that can be surfaced in a Trust Center.
  • Highlights the importance of real‑time monitoring of privileged API activity to detect unauthorized use before impact.

Recommended Actions

  1. Upgrade all mySCADA myPRO Manager instances to version 2.2 or later.
  2. Conduct an inventory of OT assets and verify that only authorized network segments can reach the command API.
  3. Deploy logging and alerting on privileged API calls; retain logs for audit purposes.
  4. Document the remediation in your control‑assurance evidence repository.

Source: CISA Advisory ICS‑A‑26‑258‑03

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →