Mitsubishi Electric GX Works3: version 1.096A or later. Mitsubishi Electric Motion Control Settings: version 1.070Y or later. Set security version to "2" in project settings. Restrict physical access to affected computers. Block remote logins from untrusted networks. Use firewalls or VPNs to prevent unauthorized access. Restrict physical and network access to authorized users only.
Quick answers
What is CVE-2026-15688?
Mitsubishi Electric GX Works3: version 1.096A or later. Mitsubishi Electric Motion Control Settings: version 1.070Y or later. Set security version to "2" in project settings. Restrict physical access to affected computers. Block remote logins from untrusted networks. Use firewalls or VPNs to prevent unauthorized access. Restrict physical and network access to authorized users only.
How severe is CVE-2026-15688?
high, CVSS 8.8
Is CVE-2026-15688 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-15688 be mitigated?
Mitsubishi Electric GX Works3: version 1.096A or later. Mitsubishi Electric Motion Control Settings: version 1.070Y or later. Set security version to "2" in project settings. Restrict physical access to affected computers. Block remote logins from untrusted networks. Use firewalls or VPNs to prevent unauthorized access. Restrict physical and network access to authorized users only.
CVSS
8.8
Vendor
Mitsubishi Electric
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
Mitsubishi Electric GX Works3, Mitsubishi Electric Motion Control Settings
Mitigation
Mitsubishi Electric GX Works3: version 1.096A or later. Mitsubishi Electric Motion Control Settings: version 1.070Y or later. Set security version to "2" in project settings. Restrict physical access to affected computers. Block remote logins from untrusted networks. Use firewalls or VPNs to prevent unauthorized access. Restrict physical and network access to authorized users only.
Mitsubishi Electric has identified a vulnerability in GX Works3 and Motion Control Settings software that could allow a local attacker to authenticate with an invalid block password and modify executable modules in memory. The issue stems from an incorrect implementation of the authentication algorithm (CWE-303). Affected versions include all releases of GX Works3 and the Motion Control Settings software packaged with it. Mitsubishi Electric has released updated versions and recommends configuring the security version to "2" in project settings as a mitigation measure.