CISA released an advisory on September 15 warning of two vulnerabilities in mySCADA myPRO Manager, industrial control software from Czechia-based mySCADA Technologies that is deployed worldwide across the critical manufacturing, energy, food and agriculture, transportation, and water and wastewater sectors.
The more severe flaw, CVE-2026-73807, carries a CVSS v3.1 score of 9.8, near the maximum critical rating. CISA said the myPRO Manager command application programming interface fails to properly enforce authentication for privileged functions, meaning an unauthenticated attacker with network access to the API could reach privileged management capabilities without credentials. A second flaw, CVE-2026-82567, allows an unauthenticated attacker to send arbitrary SMS messages through a GSM modem connected to the software’s notification gateway.
mySCADA Technologies has addressed both issues in myPRO Manager version 2.2 and is notifying connected users of the update, according to the advisory. The vulnerabilities were reported to CISA by Shirshak Secnora OU. CISA said it has not observed public exploitation of the flaws to date but urged operators to minimize internet exposure of control system devices, isolate them behind firewalls, and use virtual private networks for any required remote access.
Why it matters
myPRO Manager sits inside operational technology environments spanning energy, water and transportation, where an unauthenticated privilege gap can translate directly into physical-process risk. Asset owners should apply version 2.2 and re-confirm remote-access paths rather than assume perimeter isolation is already in place.

Leave a Reply