Back to Feed
VulnerabilitiesMar 3, 2026

Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP module and Ethernet module

Three denial-of-service vulnerabilities (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876) have been discovered in Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP and Ethernet modules, allowing remote attackers to cause DoS by sending continuous UDP packets. The vulnerabilities affect FX5-ENET/IP (versions ≤1.107) and FX5-EIP modules deployed worldwide in critical manufacturing infrastructure, with CVSS scores of 7.5 (HIGH). Mitsubishi Electric has released patches for FX5-ENET/IP v1.107+ while the fix for FX5-EIP is pending; interim mitigations include firewall restrictions, VPN, IP filtering, and network segmentation.

Summary

Three denial-of-service vulnerabilities (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876) have been discovered in Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP and Ethernet modules, allowing remote attackers to cause DoS by sending continuous UDP packets. The vulnerabilities affect FX5-ENET/IP (versions ≤1.107) and FX5-EIP modules deployed worldwide in critical manufacturing infrastructure, with CVSS scores of 7.5 (HIGH). Mitsubishi Electric has released patches for FX5-ENET/IP v1.107+ while the fix for FX5-EIP is pending; interim mitigations include firewall restrictions, VPN, IP filtering, and network segmentation.

Indicators of Compromise

  • cve — CVE-2026-1874
  • cve — CVE-2026-1875
  • cve — CVE-2026-1876