CISA

Mitsubishi Electric GX Works3 and Motion Control Settings

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs.

The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected:

Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)

Mitsubishi Electric Motion Control Settings (Software packaged with GX Works3) vers:all/* (CVE-2026-15688)

Vendor

Equipment

Mitsubishi Electric

Mitsubishi Electric GX Works3 and Motion Control Settings

Incorrect Implementation of Authentication Algorithm

Critical Infrastructure Sectors: Critical Manufacturing

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Japan

Incorrect Implementation of ...