Our takeCISA reports active exploitation in mySCADA myPRO Manager <=2.1 that lets attackers reach privileged management functions or send arbitrary SMS via connected GSM modem. OT operators: patch it now.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports that mySCADA myPRO Manager <=2.1 is actively exploited. Update to a fixed version immediately if you operate on-prem OT/SCADA environments; the flaws allow privilege escalation to management functions and arbitrary SMS via connected GSM modems.
What this means for you — Lean IT orgs:If you run mySCADA myPRO Manager on any industrial equipment, update it right away. The vulnerabilities let an attacker take control of management functions or send text messages through the connected modem.
What this means for you — MSP:Scan client environments for mySCADA myPRO Manager <=2.1 and apply the vendor update. The flaws are under active exploitation and allow privilege escalation plus arbitrary SMS through any attached GSM modem.
What this means for you — Researcher:CISA advisory ICSA-26-258-03 details two vulnerabilities (CVE-2026-73807, CVE-2026-82567) in mySCADA myPRO Manager <=2.1 under active exploitation that grant access to privileged management functions or allow arbitrary SMS via connected GSM modems.