Critical Authentication Bypass in mySCADA myPRO Manager (CVE‑2026‑73807, CVE‑2026‑82567) Threatens OT Management
What It Is – Two authentication‑related flaws in mySCADA myPRO Manager (≤ 2.1) allow an unauthenticated network attacker to invoke privileged management commands and to send arbitrary SMS messages via the attached GSM modem.
Exploitability – Both CVEs carry a CVSS v3 base score of 9.8 (Critical). Public proof‑of‑concept code has been observed, and the vendor confirms active exploitation in the wild.
Affected Products – mySCADA myPRO Manager ≤ 2.1, produced by mySCADA Technologies (global deployments in critical manufacturing, energy, food & agriculture, transportation, water & wastewater).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous verification of access‑control enforcement on OT management interfaces – a core control objective that maps to multiple frameworks (e.g., NIST CSF Identify and Protect).
- Provides auditors with concrete evidence of defensible remediation (patch status, version inventory) that can be surfaced in a Trust Center.
- Highlights the importance of real‑time monitoring of privileged API activity to detect unauthorized use before impact.
Recommended Actions
- Upgrade all mySCADA myPRO Manager instances to version 2.2 or later.
- Conduct an inventory of OT assets and verify that only authorized network segments can reach the command API.
- Deploy logging and alerting on privileged API calls; retain logs for audit purposes.
- Document the remediation in your control‑assurance evidence repository.
Source: CISA Advisory ICS‑A‑26‑258‑03