PatchSiren cyber security CVE debrief
CVE-2026-82567 mySCADA Technologies CVE debrief
CVE-2026-82567 is a vulnerability in the myPRO Manager notification gateway that allows unauthenticated attackers to send arbitrary SMS messages through a connected GSM modem. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected product deployments should be reviewed for exposure, and defenders should assess potential impact and ensure proper authentication and authorization mechanisms are in place. This vulnerability could lead to unauthorized SMS message sending, potential disruption of critical systems or services, and possible phishing or social engineering attacks.
- Vendor
- mySCADA Technologies
- Product
- mySCADA myPRO
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for securing the myPRO Manager notification gateway and ensuring the authenticity and authorization of SMS message sending should be aware of this vulnerability and take steps to verify exposure and mitigate potential impact.
Why it matters
CVE-2026-82567 is a MEDIUM-severity vulnerability in the myPRO Manager notification gateway that allows unauthenticated attackers to send arbitrary SMS messages. Defenders should prioritize verifying exposure, assessing potential impact, and ensuring proper authentication and authorization mechanisms are in place.
- Potential for unauthorized SMS message sending
- Possible disruption of critical systems or services
- Potential for phishing or social engineering attacks
- Need for verification of system configurations and authentication mechanisms
Technical summary
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. Defenders should prioritize verifying exposure of the notification gateway and assessing the potential impact of arbitrary SMS message sending on their systems.
Defensive priority
Defenders should prioritize verifying exposure of the notification gateway and assessing the potential impact of arbitrary SMS message sending on their systems.
Recommended defensive actions
- Verify exposure of the notification gateway and assess potential impact
- Review system configurations and ensure proper authentication and authorization
- Monitor for suspicious SMS message sending activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD vulnerability detail provide information on the vulnerability, but the scope of affected systems and potential impact is limited by the lack of detailed information on the myPRO Manager notification gateway and its deployment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82567 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82567
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82567 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82567
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-03.json
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03
-
Source reference
Unverified legacy reference
URL: https://www.myscada.org/downloads/mySCADAPROManager/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.