ics-otregulatorNewsThe Broadside2 min read

mySCADA myPRO Manager ships two critical auth bypasses

The CISA alert is the fourth mySCADA advisory in under two years, and the second since November 2024, to report critical-management functions shipped without authentication enforcement.


TL;DR

CISA published ICS advisory ICSA-26-258-03 flagging two vulnerabilities in mySCADA myPRO Manager versions 2.1 and below: CVE-2026-73807 (CVSS 9.8), which lets unauthenticated attackers access privileged management functions, and CVE-2026-82567 (CVSS 6.3), which exposes an unauthenticated SMS-notification endpoint reachable over the network. mySCADA Technologies patched both in version 2.2. Affected sectors include critical manufacturing, energy, food and agriculture, transportation, and water, matching the deployment profile of the prior three mySCADA advisories since November 2024. No deadline or binding update mandate accompanies the alert.

CISA's Tuesday advisory is the fourth for mySCADA products in under two years. The previous three (published November 2024, January 2025, and February 2025) each flagged authentication failures or command-injection vectors in myPRO Manager or myPRO Runtime, across the same set of critical-infrastructure sectors. The February 2025 alert (ICSA-25-044-16) carried a CVSS 10.0 for CVE-2025-24865, a missing-authentication-for-critical-function vulnerability in myPRO Manager versions prior to 1.4. The November 2024 advisory (ICSA-24-326-07) included its own CVSS 10.0 for CVE-2024-47407, an unauthenticated OS command injection. The bug class keeps recurring.

What Tuesday's advisory actually says

CVE-2026-73807 targets the command API: no authentication on privileged management functions, network-accessible, CVSS 9.8. An attacker who can reach the API gets full management control, no credentials, no trickery. CVE-2026-82567, the lower-severity companion, exposes an HTTP endpoint on the notification gateway that accepts a phone number and message without authentication and fires an SMS through any connected GSM modem. CVSS 6.3, but the operational surface matters: an attacker who can't compromise the control system can still abuse the modem to send arbitrary messages, disruption, spam, or social-engineering footholds, depending on what the modem is connected to.

mySCADA Technologies addressed both in version 2.2. Internet-connected instances receive an in-app update notification; air-gapped deployments require a manual download.

What isn't here

CISA published the advisory with no binding operational directive, no patch deadline, and no requirement that critical-infrastructure operators report their remediation status. The standard ICS boilerplate about minimizing network exposure and using VPNs appears, as it has in every mySCADA advisory since 2024. The boilerplate does not answer the question an operator actually faces: whether to take a production system offline for a manual update or accept the risk window. CISA leaves that call to the asset owner.

Who feels this

Primes and contractors running myPRO Manager in manufacturing, energy, water, food, or transportation environments. The advisory's affected-version statement covers everything at or below 2.1, which means any deployment that hasn't patched since the product's 1.x days (and there were three prior advisories giving reasons to patch) remains exposed today. The CVE-2026-73807 vector is remote, low-complexity, no user interaction. If the instance is reachable, it's ownable.


Published ·Deep Fathom