Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP module and Ethernet module
Three denial-of-service vulnerabilities (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876) have been discovered in Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP and Ethernet modules, allowing remote attackers to cause DoS by sending continuous UDP packets. The vulnerabilities affect FX5-ENET/IP (versions ≤1.107) and FX5-EIP modules deployed worldwide in critical manufacturing infrastructure, with CVSS scores of 7.5 (HIGH). Mitsubishi Electric has released patches for FX5-ENET/IP v1.107+ while the fix for FX5-EIP is pending; interim mitigations include firewall restrictions, VPN, IP filtering, and network segmentation.
Summary
Three denial-of-service vulnerabilities (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876) have been discovered in Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP and Ethernet modules, allowing remote attackers to cause DoS by sending continuous UDP packets. The vulnerabilities affect FX5-ENET/IP (versions ≤1.107) and FX5-EIP modules deployed worldwide in critical manufacturing infrastructure, with CVSS scores of 7.5 (HIGH). Mitsubishi Electric has released patches for FX5-ENET/IP v1.107+ while the fix for FX5-EIP is pending; interim mitigations include firewall restrictions, VPN, IP filtering, and network segmentation.
Indicators of Compromise
- cve — CVE-2026-1874
- cve — CVE-2026-1875
- cve — CVE-2026-1876