Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack
A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

Key points
- Mitsubishi Electric has confirmed a vulnerability, tracked as CVE-2026-13584, in its CC-Link IE TSN industrial network protocol.
- Over 80 product models are affected, including MELSEC controllers, servo drives, inverters, robot controller cards and safety modules.
- An attacker on the same network segment can send specially timed packets to tamper with communications and trigger a denial-of-service condition, meaning the equipment stops working correctly.
- All firmware versions of the listed products are affected and Mitsubishi has not yet published a patch.
- CISA reproduced the advisory in its industrial control systems bulletin; operators are told to rely on network segmentation until a fix ships.
Mitsubishi Electric has disclosed a flaw in the way its factory-floor equipment talks to itself over the network, and the list of affected gear is long.
The bug, CVE-2026-13584, sits in the CC-Link IE TSN communication protocol. That protocol is the language dozens of Mitsubishi products use to coordinate on a shop floor: programmable controllers that run machinery, servo drives that turn motors, safety modules that stop a line when something goes wrong.
An attacker who can reach the same network segment as the equipment can send carefully timed, specially crafted packets. Those packets confuse the target device into either tampering with the data it exchanges with its peers or falling over entirely. In plain terms: the machine either does the wrong thing, or it stops.
That is a denial-of-service condition, meaning legitimate control traffic no longer works. On a production line, that usually means an emergency stop and lost output. In safety-critical settings, it means a lot more paperwork.
Which products are affected?
All firmware versions of more than 80 products are affected. The list, published in Mitsubishi's advisory and echoed by the US Cybersecurity and Infrastructure Security Agency (CISA), covers most of the vendor's CC-Link IE TSN lineup.
| Product family | Example models |
|---|---|
| MELSEC MX controllers | MXR300-16, MXR500-256, MXF100-16-P32 |
| Master/local modules | RJ71GN11-T2, RJ71GN11-EIP, FX5-CCLGN-MS |
| Motion modules | RD78G4, RD78G64, RD78GHW |
| MELSERVO servo drives | MR-J5-G, MR-J5W-G, MR-JET-G |
| FR-A800/F800/E800 inverters | FR-A8NCG, FR-A800-GN, FR-E800-SCE |
| Safety remote modules | NZ2GNSS2-8D, NZ2GNSS2-16DTE |
That is not the whole list. Analog converters, FPGA modules, a tension meter, a robot controller network card and a CC-Link IE Field Network bridge module are also in scope.
Is there a patch?
No. Mitsubishi's advisory lists every affected product at "vers:all", meaning every firmware release is vulnerable, and it does not name a fixed version. Until the vendor ships firmware, operators are being told to rely on compensating controls.
Those controls are the usual industrial-network hygiene: keep the control network physically or logically separated from the office network, restrict which machines can reach the equipment, and use a firewall or a VPN, meaning an encrypted tunnel that hides traffic from anyone not authorised to see it, for any remote access.
Who found the bug?
Mitsubishi has not publicly credited a researcher in the material released so far. The advisory is coordinated through CISA's industrial control systems channel, which is the standard route for operational-technology vulnerabilities.
What should plant operators do now?
Inventory first. If any of the listed part numbers are on your floor, assume they are exploitable and check what else sits on the same network segment. An unmanaged switch shared with an office PC is a much bigger problem than a fully isolated cell.
Then watch for Mitsubishi's firmware updates and plan a maintenance window. Industrial gear rarely gets patched on a Tuesday, and windows fill up fast when a whole product family is affected at once.
Regular office users are not directly exposed by this bug (it targets industrial equipment, not laptops), but factories that go down still delay the products those users buy.



