Executive Summary
Critical vulnerabilities CVE-2026-73807 and CVE-2026-82567 were discovered in mySCADA myPRO Manager versions 2.1 and earlier, affecting industrial control systems worldwide. The first vulnerability (CVSS 9.8) allows unauthenticated attackers with network access to bypass authentication and access privileged management functions through the command API. The second vulnerability (CVSS 6.3) exposes an unauthenticated HTTP endpoint that enables attackers to send arbitrary SMS messages through connected GSM modems. These flaws impact critical infrastructure sectors including energy, manufacturing, transportation, and water systems globally.
These vulnerabilities highlight the growing threat to industrial control systems as attackers increasingly target operational technology environments. With critical infrastructure under heightened scrutiny following recent nation-state campaigns, organizations must urgently address authentication gaps in SCADA systems that could enable devastating disruptions to essential services.
Why This Matters Now
Industrial control system vulnerabilities like these are being actively exploited by nation-state actors targeting critical infrastructure. The combination of missing authentication controls and global deployment makes these systems prime targets for operational disruption campaigns.
Attack Path Analysis
Attackers exploited unauthenticated API endpoints in mySCADA myPRO Manager to gain initial access to industrial control systems. They leveraged missing authentication controls to access privileged management functions, moved laterally through connected OT networks, established command channels via exposed SMS gateway, exfiltrated sensitive operational data, and potentially disrupted critical infrastructure operations across energy, manufacturing, and water systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-73807 and CVE-2026-82567 to access unauthenticated command API and SMS gateway endpoints in mySCADA myPRO Manager systems exposed to network access
Related CVEs
CVE-2026-73807
CVSS 9.8Missing authentication in mySCADA myPRO Manager command API allows unauthenticated attackers to access privileged management functions.
Affected Products:
mySCADA Technologies myPRO Manager – <= 2.1
Exploit Status:
no public exploitCVE-2026-82567
CVSS 6.3Missing authentication in myPRO Manager notification gateway allows unauthenticated attackers to send arbitrary SMS messages through connected GSM modem.
Affected Products:
mySCADA Technologies myPRO Manager – <= 2.1
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Credential Access
Abuse Elevation Control Mechanism
Valid Accounts
Remote Services
Impair Defenses
Service Stop
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong User Authentication
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Measures
Control ID: Article 21
ISO 27001 – Access to Networks and Network Services
Control ID: A.9.1.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical SCADA vulnerabilities enable unauthenticated network access to power grid management systems, compromising operational technology controls and potentially causing widespread service disruptions.
Oil/Energy/Solar/Greentech
Missing authentication in industrial control systems exposes energy infrastructure to remote exploitation, threatening production facilities and critical energy supply chain operations globally.
Food Production
Industrial control system vulnerabilities in mySCADA systems could allow unauthorized access to food processing automation, disrupting production schedules and compromising food safety protocols.
Water and Wastewater Systems
Unauthenticated API access to SCADA management functions poses severe risks to water treatment facilities, potentially compromising public health through contamination or service interruptions.
Sources
- mySCADA myPRO Managerhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03Verified
- mySCADA Technologies myPRO Manager Download Pagehttps://www.myscada.org/downloads/mySCADAPROManager/Verified
- NVD CVE-2026-73807 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2026-73807Verified
- NVD CVE-2026-82567 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2026-82567Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained this SCADA attack by segmenting network access to industrial control systems and reducing lateral movement pathways. The attack leveraged unauthenticated API endpoints and network connectivity that could have been limited through identity-aware segmentation and controlled east-west traffic flows.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely have limited direct access to SCADA management interfaces, reducing the attack surface available to external threat actors attempting to reach industrial control endpoints
Control: Zero Trust Segmentation
Mitigation: Identity-based access policies would likely have constrained the scope of privileged functions accessible through compromised interfaces, limiting the blast radius of administrative control over industrial systems
Control: East-West Traffic Security
Mitigation: Microsegmentation policies would likely have limited lateral pathways between SCADA management systems and connected industrial networks, reducing the attacker's ability to reach additional critical infrastructure components
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls would likely have detected and constrained unauthorized communication patterns, limiting the attacker's ability to maintain persistent command channels through industrial network infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have limited the volume and scope of sensitive data exfiltration by constraining outbound network pathways and detecting unauthorized data transfer patterns from industrial control systems
While operational disruption risk would remain through compromised systems, the blast radius would likely be constrained to segmented network zones rather than cascading across entire industrial infrastructure environments
Impact at a Glance
Affected Business Functions
- Industrial Process Control
- SCADA Operations
- Critical Infrastructure Monitoring
- Emergency Notification Systems
Estimated downtime: N/A
Estimated loss: N/A
Potential unauthorized access to industrial control system management functions and SMS notification capabilities. No confirmed data breach reported.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate SCADA/OT networks from corporate networks and prevent lateral movement between critical infrastructure systems
- • Deploy Egress Security & Policy Enforcement to control and monitor all outbound communications from industrial control systems, blocking unauthorized data exfiltration
- • Enable Multicloud Visibility & Control to detect anomalous interactions and suspicious automation patterns targeting industrial management interfaces
- • Utilize East-West Traffic Security to monitor and control workload-to-workload communications within OT environments and detect privilege escalation attempts
- • Apply Encrypted Traffic (HPE) controls to protect sensitive operational data in transit between SCADA components and prevent interception of control communications



