CVE-2026-73807
CVSS 9.8 CRITICAL: the mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions.
Vulnerabilities & Exploits · Web App Attack
CISA issued an advisory for mySCADA myPRO Manager 2.1 and earlier, warning that two unauthenticated network-reachable flaws can expose privileged management functions and let an attacker send arbitrary SMS messages through a connected GSM modem. Shirshak Secnora OÜ reported the issues to CISA.
One bug leaves the command API open to remote callers without login, so admin-level actions are reachable directly over the network. The other exposes an HTTP endpoint in the notification gateway that takes a phone number and message and forwards it through the attached modem, so the product can be used as an outbound SMS channel rather than just a dashboard.
For operators in manufacturing, energy, transportation, water and wastewater, and food and agriculture, the exposure sits in the control plane and the modem link it manages. If mySCADA is bridged into operations, a network hit can reach beyond the web UI into messaging or other privileged functions until version 2.2 is in place.
1 source · Sep 15
CVSS 9.8 CRITICAL: the mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions.
CVSS 6.3 MEDIUM: the myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem.
CISA Advisories
mySCADA myPRO Manager | CISA
mySCADA myPRO Manager Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.
originalPart of the PlainSec briefing for 2026-09-16
Every edition of this story: CISA Flags mySCADA Manager Control-Plane Flaws