← Back to Feed

Mitsubishi Electric GX Works3 and Motion Control Settings

CVE-2026-15688

September 17, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs. The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected: Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688) Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3) vers:all/* (CVE-2026-15688) CVSS Vendor Equipment Vulnerabilities v3 8.8 Mitsubishi Electric Mitsubishi Electric GX Works3 and Motion Control Settings Incorrect Implementation of Authentication Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2026-15688 Incorrect Implementation of Authentication Algorithm (CWE-303) vulnerability in the affected products allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs. View CVE Details Affected Products Mitsubishi Electric GX Works3 and Motion Control Settings Vendor:Mitsubishi Electric Product Version:Mitsubishi Electric GX Works3: vers:all/*, Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3): vers:all/* Product Status:known_affected Remediations WorkaroundFor customers using GX Works3, please download version 1.096A or later from the link https://www.mitsubishielectric.com/fa/download/software/detailsearch.page?mode=software&kisyu=/plceng&shiryoid=1000001411&lang=2&select=0&softid=1&infostatus=1_2_1&viewradio=0&viewstatus=&viewpos=,...

Key Takeaways

  • Mitsubishi Electric products including CC-Link IE TSN communication protocol and GX Works3 contain vulnerabilities that could allow attackers to disrupt industrial control systems.
  • OT vulnerabilities in Mitsubishi Electric products highlight the continued risk to industrial environments from unpatched communication protocol and engineering software flaws.
  • Industrial organizations using Mitsubishi Electric equipment should apply vendor-supplied patches and implement network segmentation to isolate OT systems from IT networks.
☕ Buy a Coffee