Mitsubishi Electric GX Works3 and Motion Control Settings
CISA warns CVE-2026-15688 lets a local attacker bypass block password authentication in Mitsubishi Electric GX Works3 and tamper with control programs.
CISA republished Mitsubishi Electric advisory 2026-007 describing CVE-2026-15688, an incorrect implementation of the authentication algorithm (CWE-303) in GX Works3 and the bundled Motion Control Settings, affecting all versions. A local attacker can authenticate with an invalid block password, modify an executable module in memory, and view, tamper with, destroy, or delete control programs. CVSS v3.1 base score is 8.8 (v4.0: 9.2), and CISA recommends isolating control system networks and minimizing internet exposure.
35