Mitsubishi Electric GX Works3 and Motion Control Settings

Summary

A vulnerability (CVE-2026-15688) has been identified in Mitsubishi Electric's GX Works3 and Motion Control Settings software. Exploitation could allow a local attacker to bypass authentication, modify executable modules in memory, and gain control over critical programs.

IFF Assessment

FOE

The identified vulnerability allows attackers to bypass authentication and tamper with control programs, posing a significant risk to industrial operations.

Severity

8.8 High

The CVSS score of 8.8 reflects the severity of the vulnerability, which allows local attackers to achieve elevated privileges by bypassing authentication and subsequently tamper with, destroy, or delete critical control programs.

Defender Context

This vulnerability affects critical infrastructure, specifically the manufacturing sector, and is deployed globally. Defenders need to be aware of the potential for attackers to gain unauthorized access and manipulate industrial control systems by exploiting this authentication bypass flaw.

Read Full Story →