PatchSiren cyber security CVE debrief
CVE-2026-8806 Mitsubishi Electric Corporation CVE debrief
A HIGH severity vulnerability (CVSS Score: 8.7) was found in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP. The issue is an Expected Behavior Violation that allows a remote attacker to cause a denial-of-service (DoS) condition. By continuously sending a large number of communication packets to the Ethernet port in a short period, an attacker can increase the processing load, prevent internal anomaly-detection processing, and cause the communication function to stop. Users should take immediate action to mitigate this vulnerability.
- Vendor
- Mitsubishi Electric Corporation
- Product
- Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-19
- Original CVE updated
- 2026-06-22
- Advisory published
- 2026-06-19
- Advisory updated
- 2026-06-22
Who should care
Industrial control system (ICS) operators, particularly those using Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module, should be aware of this vulnerability. Additionally, cybersecurity professionals responsible for ICS security and network administrators managing industrial networks need to assess and mitigate this risk.
Technical summary
The vulnerability, identified as CWE-440, is caused by the product's inability to handle a large number of communication packets sent to its Ethernet port in a short period. This leads to increased processing load and prevents the product from performing internal anomaly-detection processing, ultimately causing the communication function to stop. The vulnerability has a CVSS score of 8.7, indicating a HIGH severity level.
Defensive priority
High
Recommended defensive actions
- Update the affected product with the latest firmware or patches provided by Mitsubishi Electric.
- Implement network segmentation to limit the attack surface.
- Configure firewalls and network devices to restrict unnecessary incoming traffic.
- Monitor network traffic for unusual patterns and implement intrusion detection systems.
- Develop and enforce incident response plans for ICS environments.
- Regularly review and update ICS security policies and procedures.
Evidence notes
The information provided is based on data from official sources, including CVE.org and the National Vulnerability Database (NVD). The vulnerability details were obtained from Mitsubishi Electric's PSIRT and other reliable sources. However, due to limited information available, further details about the vulnerability could not be verified.
Official resources
CVE-2026-8806 was published and modified on 2026-06-19T03:16:15.010Z.