CISA republishes advisory on GX Works3 authentication flaw
All versions of Mitsubishi Electric GX Works3 and Motion Control Settings are flagged for a critical authentication bypass, effective immediately.

On 2026-09-17 CISA issued a verbatim republication of Mitsubishi Electric advisory 2026-007, identifying CVE-2026-15688 in Mitsubishi Electric GX Works3 and the bundled Motion Control Settings software. The advisory applies to every released version of the products.
The vulnerability stems from an incorrect implementation of the authentication algorithm (CWE-303). A local attacker can authenticate with an invalid block password, execute the product, and modify part of the executable module in memory. Successful exploitation permits the attacker to view, tamper with, destroy, or delete control programs. The flaw carries a CVSS v3 base score of 8.8.
The issue was reported to Mitsubishi Electric by Mayeul Fargier, Erwan Cordier, and Noé Flatreaud. Mitsubishi Electric, headquartered in Japan, lists the affected products as deployed worldwide in the critical manufacturing sector.
CISA recommends that users minimize network exposure for all control system devices, place them behind firewalls, and isolate them from business networks. When remote access is required, organizations should employ VPNs and keep them up to date. CISA also advises conducting impact analyses and consulting the agency's industrial control systems (ICS) webpage and technical information paper ICS-TIP-12-146-01B for detailed mitigation guidance.
The advisory is provided "as-is" for informational purposes; CISA disclaims responsibility for editorial or technical accuracy and does not endorse any commercial product or service. Organizations with questions should contact Mitsubishi Electric directly.
Further reading


