All stories
highDefensive GuidanceCVE-2026-13584

Improper message integrity in Mitsubishi Electric MELSEC MX controllers enables control data manipulation

An improper message integrity flaw in several Mitsubishi Electric MELSEC MX controllers allows attackers on a CC-Link IE TSN network to manipulate control data. This vulnerability can lead to denial-of-service conditions or incorrect device operation. Defenders should isolate industrial networks and verify the integrity of communication channels.

Summary

A high-severity vulnerability has been disclosed affecting a wide array of Mitsubishi Electric MELSEC MX controllers and related industrial components. The flaw, identified as CVE-2026-13584, stems from improper enforcement of message integrity during transmission across specific communication channels.

If an attacker gains access to a CC-Link IE TSN network, they can inject specially crafted packets under specific timing conditions. This interference allows for the tampering of control input/output values, which may result in a denial-of-service (DoS) state or cause industrial hardware to operate incorrectly.

Technical Details

The vulnerability resides in how the communication channel handles message integrity. Because the system fails to properly validate the integrity of incoming messages during transmission, it is susceptible to manipulation by any actor with network access.

The impact is highly dependent on the specific hardware being targeted. The flaw affects various modules including:

  • MELSEC MX Controller MX-R and MX-F models
  • CC-Link IE TSN interface boards and expansion units
  • Motion modules and Control Boards
  • Inverters (FR-A800/F800/E800 Series)
  • Industrial Robot CR800-D series controllers
  • Various LSI devices and software kits used for Master/Local module communication

An attacker targeting these components can disrupt the control function by altering the data that dictates how a machine or motor responds to commands.

Affected Products

The vulnerability impacts a broad spectrum of Mitsubishi Electric industrial products, specifically those utilizing CC-Link IE TSN or related communication protocols.

Product Category Affected Models/Series
Controllers MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model
Motion & Control Motion module, Motion Control Software, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET
Communication Hardware CC-Link IE TSN interface board, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module
Industrial Computing Industrial Computer MELIPC series, GOT3000 Series
Specialized Modules Analog-Digital converter module, Digital-Analog converter module, Tension meter

Why this matters for defenders

For operators of industrial automation lines, this vulnerability represents a direct risk to process stability. Because the attack relies on "specific timing conditions," an attacker must have precise knowledge of the network traffic or be able to observe it to successfully inject the tampered packets.

The primary consequence is the loss of predictable control. If a controller receives manipulated input/output values, it may trigger an emergency stop (DoS) or, more dangerously, execute unintended physical movements that deviate from the programmed logic. This makes the integrity of the CC-Link IE TSN network a critical security boundary.

Defender guidance

Securing these environments requires focusing on network segmentation and traffic validation.

  • Isolate Industrial Networks: Ensure that CC-Link IE TSN networks are strictly isolated from corporate networks and the public internet. Access to these control networks should be restricted to authorized engineering workstations only.
  • Monitor Network Timing and Traffic: Since the exploit relies on specific timing, monitoring for unusual network jitter or unexpected packet injection patterns may provide early warning of an attempted manipulation.
  • Verify Communication Integrity: Where possible, implement secondary validation methods for critical control signals to ensure that the data received by a module matches the intended command sent by the master controller.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07
  2. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -