Vulnerabilities & Exploits · Web App Attack

CISA Flags mySCADA Manager Control-Plane Flaws

CISA issued an advisory for mySCADA myPRO Manager 2.1 and earlier, warning that two unauthenticated network-reachable flaws can expose privileged management functions and let an attacker send arbitrary SMS messages through a connected GSM modem. Shirshak Secnora OÜ reported the issues to CISA.

One bug leaves the command API open to remote callers without login, so admin-level actions are reachable directly over the network. The other exposes an HTTP endpoint in the notification gateway that takes a phone number and message and forwards it through the attached modem, so the product can be used as an outbound SMS channel rather than just a dashboard.

For operators in manufacturing, energy, transportation, water and wastewater, and food and agriculture, the exposure sits in the control plane and the modem link it manages. If mySCADA is bridged into operations, a network hit can reach beyond the web UI into messaging or other privileged functions until version 2.2 is in place.

1 source · Sep 15

CVE-2026-73807

NVD KEV

CVSS 9.8 CRITICAL: the mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions.

CVE-2026-82567

NVD KEV

CVSS 6.3 MEDIUM: the myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem.

Timeline

Sources

Part of the PlainSec briefing for 2026-09-16

Every edition of this story: CISA Flags mySCADA Manager Control-Plane Flaws

More from today