Mitsubishi Electric GX Works3 and Motion Control Settings
Mitsubishi Electric has issued a security advisory regarding a critical vulnerability (CVE-2026-15688) in its GX Works3 and Motion Control Settings software. This vulnerability allows a local attacker to bypass authentication and potentially tamper with or delete control programs. The advisory details workarounds and mitigations, emphasizing the need to restrict network access and implement robust security measures to prevent exploitation.
Mitsubishi Electric has identified a critical vulnerability (CVE-2026-15688) within its GX Works3 and Motion Control Settings software, impacting all versions. This vulnerability, classified as an Incorrect Implementation of Authentication Algorithm (CWE-303), enables a local attacker to successfully authenticate even with an invalid block password. The affected products are used in critical infrastructure sectors, specifically critical manufacturing.
Mitsubishi Electric recommends a workaround: for customers using GX Works3, install version 1.096A or later, and set the security version for projects to "2". For Motion Control Settings, install version 1.070Y or later, and set the security version for projects to "2".
To mitigate the risk, Mitsubishi Electric advises restricting network exposure for control system devices, isolating them from business networks, and utilizing secure remote access methods like VPNs (recognizing VPN vulnerabilities). Furthermore, preventing users from clicking on links in untrusted emails and installing antivirus software are recommended.
This vulnerability is classified as high severity due to its potential impact on critical manufacturing operations. The CISA advisory emphasizes the importance of proactive defense strategies and encourages organizations to perform impact analysis and risk assessments.