{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/myscada-technologies/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mySCADA myPRO Manager (\u003c=2.1)"],"_cs_severities":["high"],"_cs_tags":["ics","scada","vulnerability","cve"],"_cs_type":"threat","_cs_vendors":["mySCADA Technologies"],"content_html":"\u003cp\u003emySCADA Technologies has disclosed two critical vulnerabilities in its myPRO Manager software, versions 2.1 and earlier. These vulnerabilities, tracked as CVE-2026-73807 and CVE-2026-82567, expose the management API and notification gateway to unauthenticated network access. CVE-2026-73807 (CWE-862) allows an unauthenticated attacker to invoke privileged management functions within the command API. CVE-2026-82567 (CWE-306) exposes an unauthenticated HTTP endpoint in the notification gateway that permits sending arbitrary SMS messages through a connected GSM modem. These flaws affect critical infrastructure sectors including Energy, Transportation, and Water management. Defenders should prioritize updating to version 2.2 and restricting network access to these interfaces to prevent unauthorized control or messaging.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could lead to full unauthorized access to system management functions or the abuse of communication channels (GSM modems) to send unauthorized SMS messages. These vulnerabilities affect organizations across critical infrastructure sectors such as Energy, Food and Agriculture, and Water and Wastewater, posing risks to operational continuity and system integrity if accessed by malicious actors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade mySCADA myPRO Manager to version 2.2 or later immediately to patch CVE-2026-73807 and CVE-2026-82567.\u003c/li\u003e\n\u003cli\u003eIsolate the myPRO Manager notification gateway and command API from public internet access by placing them behind firewalls or VPNs.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the management interfaces to authorized management workstations only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T16:31:21Z","date_published":"2026-09-15T16:31:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-myscada-pro-manager/","summary":"Multiple vulnerabilities in mySCADA myPRO Manager versions 2.1 and earlier allow unauthenticated attackers to execute arbitrary management commands or send unauthorized SMS messages.","title":"Authentication and Authorization Vulnerabilities in mySCADA myPRO Manager","url":"https://feed.craftedsignal.io/briefs/2026-09-myscada-pro-manager/"}],"language":"en","title":"CraftedSignal Threat Feed - MySCADA Technologies","version":"https://jsonfeed.org/version/1.1"}