mySCADA myPRO Manager Missing Authentication Vulnerabilities
First seen Sep 16, 2026 · Updated Sep 16, 2026 · CVSS 9.8
mySCADA myPRO Manager versions 2.1 and earlier contain two vulnerabilities allowing unauthenticated attackers with network access to bypass authentication and access privileged management functions, or send arbitrary SMS messages via a connected GSM modem. The critical flaw (CVE-2026-73807, CVSS 9.8) enables full compromise of privileged command functions without credentials, posing a severe risk to industrial control environments across multiple critical infrastructure sectors.
Technical Analysis
CVE-2026-73807 (CWE-862, CVSS 3.1: 9.8) results from the myPRO Manager command API failing to enforce authentication on privileged management functions, allowing an unauthenticated network attacker to fully control affected systems (confidentiality, integrity, and availability all rated High). CVE-2026-82567 (CWE-306, CVSS 3.1: 6.3) exposes an unauthenticated HTTP endpoint in the notification gateway that accepts arbitrary phone numbers and messages, enabling abuse of the connected GSM modem to send unauthorized SMS. Both vulnerabilities require only network access with no authentication or user interaction, making them trivially exploitable against internet-exposed or improperly segmented SCADA management systems. This is a traditional ICS/OT vulnerability with no direct AI agent tooling component; however, organizations that deploy LLM-based agents or automation frameworks to monitor, orchestrate, or remediate SCADA/ICS environments should treat any host running myPRO Manager as a high-value target, since agent credentials or API keys used for ICS integration could be exposed or abused if the management API is compromised.
Affected Systems
mySCADA myPRO Manager versions <=2.1 (all deployments across Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, and Water and Wastewater sectors, deployed worldwide; vendor headquartered in Czechia)
Indicators of Compromise
- No known IOCs published; no known public exploitation reported by CISA at this time.
Remediation Steps
- 1
Upgrade to Version 2.2
Update mySCADA myPRO Manager to version 2.2 or later, which addresses both CVE-2026-73807 and CVE-2026-82567. Download from https://www.myscada.org/downloads/mySCADAPROManager/ if the device is not internet-connected for automatic update notifications.
- 2
Restrict Network Exposure
Ensure myPRO Manager and all associated control system devices are not accessible from the internet; place them behind firewalls and segment them from business/IT networks.
- 3
Use Secure Remote Access
If remote access is required, use up-to-date VPN solutions rather than exposing management APIs directly, and recognize VPN security depends on the security of connected endpoints.
- 4
Monitor and Report
Monitor for unauthorized access attempts to the command API and notification gateway, and report any suspected malicious activity to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.