CISA has disclosed two vulnerabilities in mySCADA myPRO Manager, affecting versions 2.1 and earlier. CVE-2026-73807 is rated critical, with a CVSSv3 score of 9.8, while CVE-2026-82567 has a score of 6.3. Both are classified as missing-authorisation flaws and could affect industrial control environments using the platform.
CVE-2026-73807 affects the command API, which does not properly enforce authentication for privileged functions. An attacker with network access could therefore reach restricted management functions without credentials. CVE-2026-82567 concerns the notification gateway, which exposes an unauthenticated HTTP endpoint for sending SMS messages through a connected GSM modem. CISA said there is no confirmed exploitation or public proof of concept for either vulnerability.
mySCADA Technologies has fixed the defects in version 2.2. Administrators should upgrade installations running version 2.1 or earlier. Where an immediate update is not possible, the article recommends isolating control-system networks behind firewalls.