A flaw in Mitsubishi factory networks lets attackers scramble the machines

CVE-2026-13584 hits more than 80 Mitsubishi Electric products that speak CC-Link IE TSN, the protocol wiring modern factory floors together.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal editorial shot of a modern automotive factory floor at low light, focused on a row of industrial control cabinets with blinkin
Share

Key points

  • A single flaw, CVE-2026-13584, affects more than 80 Mitsubishi Electric industrial products that share a common factory-floor network protocol, and every version of each listed product is vulnerable.
  • The bug scores 7.1 out of 10 on the standard severity scale and was published on 30 July 2026.
  • An attacker already on the same network can send specially timed packets to tamper with control signals or knock the equipment offline.
  • Affected gear spans safety modules and servo drives to robot controllers and the MELSEC MX programmable controllers at the heart of many production lines.
  • No patched version is listed in the advisory; Mitsubishi points operators to network-level defences while a fix is prepared.

Mitsubishi Electric has disclosed a weakness in the way dozens of its factory-floor products communicate. CC-Link IE TSN is the industrial networking protocol letting programmable controllers, motors and safety modules trade data in near real time on a production line. The protocol doesn't properly verify that messages crossing the network haven't been altered in transit. Someone who can reach that network can send carefully timed packets and either change the values a controller acts on, or stop it working entirely.

That's what security people call a denial-of-service condition. On a factory floor it can mean a stalled line, a mis-fed robot arm, or a safety module that no longer behaves as its operators expect.

What exactly is broken?

The vulnerability, tracked as CVE-2026-13584, is an "improper enforcement of message integrity" bug. The network doesn't do a strong enough job of confirming that a message came from where it claims and hasn't been altered in flight.

It carries a severity score of 7.1 out of 10, firmly in the "high" band without reaching critical. The score stays below critical because the attacker needs a foothold on the CC-Link IE TSN network itself; they can't reach it from the open internet. Cold comfort for anyone who's watched an operational-technology network go flat after a single engineering laptop got phished.

We first covered this advisory on 30 July 2026; CISA has since updated it with the fuller product list below.

Which products are affected?

Almost everything Mitsubishi makes that speaks this protocol. CISA lists more than eighty distinct product families, every firmware version of each marked vulnerable.

Product family Example models
MELSEC MX programmable controllers MXR300-16, MXR500-256, MXF100S-P32
Master and local network modules RJ71GN11-T2, RJ71GN11-EIP, FX5-CCLGN-MS
Motion modules and boards RD78G4, RD78GHW, MR-EM441G
Safety remote modules NZ2GNSS2-8D, NZ2GNSS2-16DTE-K
MELSERVO servo drives MR-J5-G, MR-JET-G, MR-MD333G
Robot controller network card CR800-D Network Base Card

Also on the list: analog-to-digital converters, tension meters used in printing and web-handling lines, MELIPC industrial computers and GOT3000 operator panels. If your integrator picked Mitsubishi for the network backbone, assume you have exposure somewhere.

What should operators actually do?

Segment the network and lock down who can reach it. There's no firmware fix in the advisory, so the mitigation is entirely at the network layer: keep CC-Link IE TSN traffic off any segment that also touches office IT or remote-access tools, and log everything that crosses the boundary.

Multi-factor authentication won't help here. This isn't a login flaw. It's a protocol-integrity problem, closer in spirit to old ARP-spoofing and BGP-hijack issues than to anything in the identity world. The right fix is a message authentication code baked into the protocol itself, and that's on Mitsubishi to ship.

Should you worry?

The scary line in this advisory isn't the CVSS number. It's the "vers:all" next to every single product. There's no clean version to upgrade to yet, and the Minnesota water-utility attack on 29 July is a recent reminder of what happens when industrial control networks get treated as IT-adjacent rather than isolated. Until Mitsubishi ships a fix, the network perimeter is the patch.

© 2026 Threat Vectr