PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8806 Mitsubishi Electric Corporation CVE debrief

A HIGH severity vulnerability (CVSS Score: 8.7) was found in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP. The issue is an Expected Behavior Violation that allows a remote attacker to cause a denial-of-service (DoS) condition. By continuously sending a large number of communication packets to the Ethernet port in a short period, an attacker can increase the processing load, prevent internal anomaly-detection processing, and cause the communication function to stop. Users should take immediate action to mitigate this vulnerability.

Vendor
Mitsubishi Electric Corporation
Product
Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-19
Original CVE updated
2026-06-22
Advisory published
2026-06-19
Advisory updated
2026-06-22

Who should care

Industrial control system (ICS) operators, particularly those using Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module, should be aware of this vulnerability. Additionally, cybersecurity professionals responsible for ICS security and network administrators managing industrial networks need to assess and mitigate this risk.

Technical summary

The vulnerability, identified as CWE-440, is caused by the product's inability to handle a large number of communication packets sent to its Ethernet port in a short period. This leads to increased processing load and prevents the product from performing internal anomaly-detection processing, ultimately causing the communication function to stop. The vulnerability has a CVSS score of 8.7, indicating a HIGH severity level.

Defensive priority

High

Recommended defensive actions

  • Update the affected product with the latest firmware or patches provided by Mitsubishi Electric.
  • Implement network segmentation to limit the attack surface.
  • Configure firewalls and network devices to restrict unnecessary incoming traffic.
  • Monitor network traffic for unusual patterns and implement intrusion detection systems.
  • Develop and enforce incident response plans for ICS environments.
  • Regularly review and update ICS security policies and procedures.

Evidence notes

The information provided is based on data from official sources, including CVE.org and the National Vulnerability Database (NVD). The vulnerability details were obtained from Mitsubishi Electric's PSIRT and other reliable sources. However, due to limited information available, further details about the vulnerability could not be verified.

Official resources

CVE-2026-8806 was published and modified on 2026-06-19T03:16:15.010Z.