mySCADA myPRO Manager: Two Missing-Authorization Flaws in an ICS Management Platform
CISA warned about two missing-authorization vulnerabilities in mySCADA myPRO Manager — CVE-2026-73807 (CVSS 9.8) and CVE-2026-82567 (CVSS 6.3). Both allow acting without credentials if network access is available; a fix was released in version 2.2, and no exploitation cases have been recorded.
- CVE-2026-73807 (CVSS 9.8): command API does not check rights for privileged functions
- CVE-2026-82567 (CVSS 6.3): SMS gateway HTTP endpoint without authentication
- Versions 2.1 and older are vulnerable, fix in version 2.2
- ZoomEye found 651 internet-accessible assets with mySCADA header
Read next
Security