A flaw in Mitsubishi factory networks lets attackers scramble the machines
CVE-2026-13584 hits more than 80 Mitsubishi Electric products that speak CC-Link IE TSN, the protocol wiring modern factory floors together.

Key points
- A single flaw, CVE-2026-13584, affects more than 80 Mitsubishi Electric industrial products that share a common factory-floor network protocol, and every version of each listed product is vulnerable.
- The bug scores 7.1 out of 10 on the standard severity scale and was published on 30 July 2026.
- An attacker already on the same network can send specially timed packets to tamper with control signals or knock the equipment offline.
- Affected gear spans safety modules and servo drives to robot controllers and the MELSEC MX programmable controllers at the heart of many production lines.
- No patched version is listed in the advisory; Mitsubishi points operators to network-level defences while a fix is prepared.
Mitsubishi Electric has disclosed a weakness in the way dozens of its factory-floor products communicate. CC-Link IE TSN is the industrial networking protocol letting programmable controllers, motors and safety modules trade data in near real time on a production line. The protocol doesn't properly verify that messages crossing the network haven't been altered in transit. Someone who can reach that network can send carefully timed packets and either change the values a controller acts on, or stop it working entirely.
That's what security people call a denial-of-service condition. On a factory floor it can mean a stalled line, a mis-fed robot arm, or a safety module that no longer behaves as its operators expect.
What exactly is broken?
The vulnerability, tracked as CVE-2026-13584, is an "improper enforcement of message integrity" bug. The network doesn't do a strong enough job of confirming that a message came from where it claims and hasn't been altered in flight.
It carries a severity score of 7.1 out of 10, firmly in the "high" band without reaching critical. The score stays below critical because the attacker needs a foothold on the CC-Link IE TSN network itself; they can't reach it from the open internet. Cold comfort for anyone who's watched an operational-technology network go flat after a single engineering laptop got phished.
We first covered this advisory on 30 July 2026; CISA has since updated it with the fuller product list below.
Which products are affected?
Almost everything Mitsubishi makes that speaks this protocol. CISA lists more than eighty distinct product families, every firmware version of each marked vulnerable.
| Product family | Example models |
|---|---|
| MELSEC MX programmable controllers | MXR300-16, MXR500-256, MXF100S-P32 |
| Master and local network modules | RJ71GN11-T2, RJ71GN11-EIP, FX5-CCLGN-MS |
| Motion modules and boards | RD78G4, RD78GHW, MR-EM441G |
| Safety remote modules | NZ2GNSS2-8D, NZ2GNSS2-16DTE-K |
| MELSERVO servo drives | MR-J5-G, MR-JET-G, MR-MD333G |
| Robot controller network card | CR800-D Network Base Card |
Also on the list: analog-to-digital converters, tension meters used in printing and web-handling lines, MELIPC industrial computers and GOT3000 operator panels. If your integrator picked Mitsubishi for the network backbone, assume you have exposure somewhere.
What should operators actually do?
Segment the network and lock down who can reach it. There's no firmware fix in the advisory, so the mitigation is entirely at the network layer: keep CC-Link IE TSN traffic off any segment that also touches office IT or remote-access tools, and log everything that crosses the boundary.
Multi-factor authentication won't help here. This isn't a login flaw. It's a protocol-integrity problem, closer in spirit to old ARP-spoofing and BGP-hijack issues than to anything in the identity world. The right fix is a message authentication code baked into the protocol itself, and that's on Mitsubishi to ship.
Should you worry?
The scary line in this advisory isn't the CVSS number. It's the "vers:all" next to every single product. There's no clean version to upgrade to yet, and the Minnesota water-utility attack on 29 July is a recent reminder of what happens when industrial control networks get treated as IT-adjacent rather than isolated. Until Mitsubishi ships a fix, the network perimeter is the patch.



