Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack
A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

Key points
- Mitsubishi Electric has confirmed a vulnerability, tracked as CVE-2026-13584, in its CC-Link IE TSN industrial network protocol.
- More than 80 product models are affected, including MELSEC controllers, servo drives, inverters and safety modules.
- An attacker on the same network segment can send specially timed packets to tamper with communications and trigger a denial-of-service condition, meaning the equipment stops working correctly.
- All firmware versions of the listed products are vulnerable and Mitsubishi has not yet published a patch.
- CISA reproduced the advisory in its industrial control systems bulletin; operators are told to rely on network segmentation until a fix ships.
Mitsubishi Electric has disclosed a flaw in the way its factory-floor equipment communicates over the network, and the list of affected gear is long.
The bug, CVE-2026-13584, sits in the CC-Link IE TSN communication protocol. That's the language dozens of Mitsubishi products use to coordinate on a shop floor: programmable controllers that run machinery, servo drives that turn motors, safety modules that stop a line when something goes wrong.
An attacker who can reach the same network segment can send carefully timed, specially crafted packets that confuse the target device into either corrupting the data it exchanges with peers or failing entirely. The machine either does the wrong thing, or it stops.
On a production line that usually means an emergency stop and lost output. In safety-critical settings, the consequences are harder to contain. Rockwell faced a structurally similar problem in July, when a malformed packet could knock its Flex 5000 Adapter offline until someone power-cycled it. Mitsubishi's exposure is broader: no patch exists yet.
Which products are affected?
All firmware versions of more than 80 products are affected. The list, published in Mitsubishi's advisory and echoed by the US Cybersecurity and Infrastructure Security Agency (CISA), covers most of the vendor's CC-Link IE TSN lineup.
| Product family | Example models |
|---|---|
| MELSEC MX controllers | MXR300-16, MXR500-256, MXF100-16-P32 |
| Master/local modules | RJ71GN11-T2, RJ71GN11-EIP, FX5-CCLGN-MS |
| Motion modules | RD78G4, RD78G64, RD78GHW |
| MELSERVO servo drives | MR-J5-G, MR-J5W-G, MR-JET-G |
| FR-A800/F800/E800 inverters | FR-A8NCG, FR-A800-GN, FR-E800-SCE |
| Safety remote modules | NZ2GNSS2-8D, NZ2GNSS2-16DTE |
Analog converters, FPGA modules, tension meters, a robot controller network card and a CC-Link IE Field Network bridge module are also in scope.
Is there a patch?
No. Mitsubishi's advisory lists every affected product at "vers:all", meaning every firmware release is vulnerable, with no fixed version named. Until the vendor ships firmware, operators are being told to rely on compensating controls.
Those controls are standard industrial-network hygiene: keep the control network physically or logically separated from the office network, restrict which machines can reach the equipment, and use a firewall or a VPN, meaning an encrypted tunnel, for any remote access.
Who found the bug?
Mitsubishi hasn't publicly credited a researcher in the material released so far. The advisory is coordinated through CISA's industrial control systems channel, which is the standard route for operational-technology vulnerabilities.
What should plant operators do now?
Inventory first. If any listed part numbers are on your floor, assume they're exploitable and check what else sits on the same network segment. An unmanaged switch shared with an office PC is a much bigger problem than a fully isolated cell.
Then watch for Mitsubishi's firmware updates and plan a maintenance window. Industrial gear rarely gets patched quickly, and windows fill fast when a whole product family is affected at once. This one covers controllers, drives, safety modules and analog converters simultaneously, which makes coordinating downtime genuinely difficult.



