CISA Issues Two Mitsubishi Electric Advisories: CC-Link IE TSN Packet Tampering and GX Works3 Block Password Bypass (CVE-2026-15688)
CISA published two Mitsubishi Electric advisories dated 2026-09-17: an updated ICSA-26-211-07 (Update A) warning that segment-attached attackers can tamper with CC-Link IE TSN control data via crafted packets under specific timing conditions, and a…
CISA updated its advisory ICSA-26-211-07 (Update A) on a CWE-924 improper enforcement of message integrity flaw in the Mitsubishi Electric CC-Link IE TSN communication protocol. An attacker on the same network segment can send specially crafted packets under specific timing conditions to tamper with control input and output values, causing incorrect operation or denial of service in affected products. Affected products span numerous models, including MELSEC MX controllers, RJ71GN11 modules, motion modules (RD78G/LD78G), FX5 units, and NZ2GN block-type remote modules. Separately, CISA republished Mitsubishi Electric advisory 2026-007 describing CVE-2026-15688, an incorrect implementation of the authentication algorithm (CWE-303) in GX Works3 and the bundled Motion Control Settings, affecting all versions. A local attacker can authenticate with an invalid block password, modify an executable module in memory, and view, tamper with, destroy, or delete control programs. The flaw has a CVSS v3.1 base score of 8.8 and a v4.0 score of 9.2. CISA recommends isolating control system networks and minimizing internet exposure. The two reports cover distinct vulnerabilities and contain no conflicting facts.
- ICSA-26-211-07 Update A: CWE-924 improper enforcement of message integrity in the CC-Link IE TSN communication protocol
- Segment-attached attackers can send specially crafted packets under specific timing conditions to tamper with control I/O values, causing incorrect operation or denial of service
- Affected CC-Link IE TSN products include MELSEC MX controllers, RJ71GN11 modules, motion modules (RD78G/LD78G), FX5 units, and NZ2GN block-type remote modules
- CVE-2026-15688 (Mitsubishi Electric advisory 2026-007): CWE-303 incorrect implementation of authentication algorithm in GX Works3 and bundled Motion Control Settings; all versions affected
- A local attacker can authenticate with an invalid block password, modify an executable module in memory, and view, tamper with, destroy, or delete control programs
- CVE-2026-15688 scores 8.8 on CVSS v3.1 and 9.2 on CVSS v4.0
- CISA mitigation guidance: isolate control system networks and minimize internet exposure
- Both advisories were published/updated by CISA on 2026-09-17
Coverage timelineoldest first · each row is one article
- · 1d agoMitsubishi Electric GX Works3 and Motion Control Settings
CISA Advisories· 35
CISA warns CVE-2026-15688 lets a local attacker bypass block password authentication in Mitsubishi Electric GX Works3 and tamper with control programs.
- · 1d agoMitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)
CISA Advisories· 42
CISA updated its CC-Link IE TSN advisory: segment-attached attackers can tamper with Mitsubishi Electric control data and trigger denial of service conditions.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15688 | Block password bypass in Mitsubishi Electric GX Works3 and Motion Control Setting Mitsubishi Electric's GX Works3 and Motion Control Setting engineering software implement the block password feature incorrectly (CWE-303), so authentication succeeds even with an invalid password. A local attacker with low privileges who can execute the affected software can modify part of the executable module in memory to bypass the password check. Once bypassed, the attacker can view, tamper with, destroy, or delete PLC control programs that the password was meant to protect. Any organization running the affected software on engineering workstations with access to MELSEC PLC environments is affected, since the attack requires only local access to the workstation. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA KEV. Do: Inventory engineering workstations running GX Works3 and Motion Control Setting and upgrade to the fixed versions listed in Mitsubishi Electric's advisory for CVE-2026-15688. Until patched, restrict local logon and software execution on OT engineering workstations and treat the block password as change control rather than a security boundary. Audit control programs for unauthorized modifications and monitor for processes tampering with the GX Works3 executable in memory. | 9.2 | — |
| large≈100,000+ engineering workstation installs worldwide (order of magnitude 10^5) |