Threat reportICS/SCADATL-2026-1874

Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876)

highACTIVE

Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP (TL-2026-1874) is a high-severity ICS/SCADA threat scored CVSS 8.7, first published 2026-08-04. It has no confirmed attribution, affects Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module, references 4 CVEs (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876), maps to 4 MITRE ATT&CK techniques (T0814, T0822, T1190), and is covered by 9 detection rules and 2 indicators of compromise.

CVSS
8.7/10High
CVEs
4Referenced vulnerabilities
Techniques
4MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
2Indicators of compromise

Key facts for TL-2026-1874

Threat ID
TL-2026-1874
Severity
HIGH
CVSS
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
Status
ACTIVE
Category
ICS_SCADA
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
manufacturing, critical-infrastructure, water-and-wastewater, energy, automotive, food-and-beverage
Target regions
Global
Detection rules
9
Indicators of compromise
2

Malware and tooling in Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP

Malware and tooling: Scapy, hping3

How Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP works

Multiple remotely exploitable denial-of-service (DoS) vulnerabilities affect Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet modules and FX5-EIP EtherNet/IP modules. A remote, unauthenticated attacker can continuously send UDP packets to an exposed module, causing uncontrolled receive-buffer consumption or resource-exhaustion (CWE-670 / CWE-404) that forces the PLC network module into a DoS state from which a manual system reset is required to recover. CISA rated the flaws CVSS 4.0 8.7 (HIGH) in advisory ICSA-26-62-01; internet-facing industrial devices are the primary risk.

The Mitsubishi Electric MELSEC iQ-F Series is a widely deployed programmable logic controller (PLC) family used across manufacturing, water/wastewater, energy, and critical infrastructure. Its FX5-ENET/IP Ethernet module and FX5-EIP EtherNet/IP module expose the ODVA Common Industrial Protocol (CIP) over EtherNet/IP, which uses UDP/TCP encapsulation on port 44818 and implicit I/O messaging on UDP port 2222. CISA advisory ICSA-26-62-01 (published 2026-03-03) and Mitsubishi Electric PSIRT advisory 2025-021 disclose three related DoS vulnerabilities that share a single, trivially automatable attack vector: a remote attacker sends a continuous stream of UDP packets to the module, which the device fails to handle correctly, leading to uncontrolled receive-buffer consumption or improper resource shutdown/release. Recovery from the resulting outage requires a manual system reset of the module; the PLC process under control is disrupted in the interim.

CVE-2026-1874 (CWE-670, Always-Incorrect Control Flow Implementation) affects the FX5-ENET/IP module, firmware versions 1.106 and prior. Continuous UDP packet reception consumes the receive buffer without bound until memory is exhausted, forcing a DoS. It is fixed in firmware version 1.107 or later. CVE-2026-1875 (CWE-404, Improper Resource Shutdown or Release) affects the FX5-EIP module, versions 1.000 and prior, fixed in version 1.001 or later. CVE-2026-1876 (CWE-404) affects all versions of the FX5-ENET/IP module; as of the JVN update of 2026-04-23 the vendor has stated no patched firmware is planned for this flaw, leaving only mitigations. A closely related fourth flaw, CVE-2026-8806 (CWE-440, Expected Behavior Violation) in the FX5-ENET/IP line, also has no fix planned; technical analysis describes a real-time scheduling starvation condition in which a high-priority EtherNet/IP protocol task preempts the lower-priority internal anomaly-detection task indefinitely (a priority-inversion scenario), after which the module's internal supervisor declares the communication function unhealthy and shuts it down. On a 100 Mbps link the ratio tips at roughly 40,000 packets/sec (~27 Mbps), easily achieved from a compromised HMI or engineering workstation.

All four CVEs score CVSS 4.0 8.7 (HIGH) with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N and CVSS 3.1 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The NVD-referenced CISA-ADP SSVC assessment rates exploitation as 'none' (no confirmed in-the-wild exploitation), automatable as 'yes', and technical impact as 'partial'. CVE-2026-1874 is NOT in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the 2026-07-21 KEV update. No named threat actor has been publicly confirmed exploiting these specific CVEs; however, the adjacent ICS/OT threat landscape is directly relevant: the IRGC-affiliated CyberAv3ngers demonstrated the Unitronics internet-exposed-PLC attack playbook in AA23-335A, the FrostyGoop malware weaponized Modbus TCP/502 against 46,000+ exposed devices in Ukraine, and Forescout documented the Ramnit worm infecting legitimate Mitsubishi GX Works engineering-workstation executables. Defense therefore centers on asset exposure reduction, network segmentation, firmware patch management, and high-rate UDP/EtherNet/IP packet-rate detection.

MITRE ATT&CK techniques used in TL-2026-1874

inhibit-response-function

T0814 Denial of Service; T1691.001 Command Message

initial-access

T0822 External Remote Services

Initial Access

T1190 Exploit Public-Facing Application

Affected products and versions in Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP

  • Mitsubishi Electric — MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
    Vulnerable versions: up to 1.106 (CVE-2026-1874); all versions (CVE-2026-1876)
    Fixed in: 1.107 and later (CVE-2026-1874); no fix planned (CVE-2026-1876)
  • Mitsubishi Electric — MELSEC iQ-F Series FX5-EIP EtherNet/IP Module
    Vulnerable versions: 1.000 and prior
    Fixed in: 1.001 and later

Remediation for Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP

Patches

  • Update FX5-ENET/IP firmware to version 1.107 or later (CVE-2026-1874)
  • Update FX5-EIP firmware to version 1.001 or later (CVE-2026-1875)
  • For CVE-2026-1876 and CVE-2026-8806 (no fix planned), migrate from FX5-ENET/IP to the successor FX5-EIP module

Immediate actions

  • Remove internet exposure of FX5-ENET/IP and FX5-EIP modules; block inbound UDP/TCP port 44818 and UDP port 2222 from untrusted networks at the perimeter firewall
  • Enable the module's IP filter function to restrict EtherNet/IP access to trusted hosts/IP ranges
  • Place control-system networks behind firewalls and isolate them from business networks via OT network segmentation
  • Monitor for and alert on high-rate UDP traffic to 44818/2222 and abnormal PLC protective-restart cycles

Workarounds

  • Restrict physical access to the module and connected network equipment
  • Install antivirus on engineering PCs that access the affected product
  • Operate the affected product within a LAN only and block untrusted network hosts

Longer-term hardening

  • Use a VPN for any remote access into the control network and keep VPN appliances patched
  • Deploy ICS-aware intrusion detection (e.g., Zeek/Suricata EtherNet/IP dissectors) with packet-rate and buffer-exhaustion alerts
  • Inventory and continuously manage the firmware baseline of all MELSEC iQ-F network modules
  • Perform an impact/risk assessment before deploying any defensive measures, per CISA guidance

CVEs associated with Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP

CVE-2026-1874, CVE-2026-1875, CVE-2026-1876, CVE-2026-8806

Weaknesses (CWE) in Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP

CWE-670, CWE-404

Timeline of Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP

  • CISA publishes ICS advisory ICSA-26-62-01; CVEs CVE-2026-1874, CVE-2026-1875, and CVE-2026-1876 are published in NVD with CVSS 4.0 8.7 (HIGH).
  • Mitsubishi Electric PSIRT publishes security advisory 2025-021 detailing the affected FX5-ENET/IP and FX5-EIP modules and fixed firmware versions.
  • JVN#JVNVU93286687 is updated to state that CVE-2026-1876 (FX5-ENET/IP, all versions) has no planned firmware fix, hardening the vendor's position to mitigations-only.
  • NVD records for CVE-2026-1874/1875/1876 are last modified; CISA-ADP SSVC assessment confirms exploitation 'none', automatable 'yes', technical impact 'partial'.
  • Mitsubishi PSIRT advisory 2026-002 discloses CVE-2026-8806 (FX5-ENET/IP all versions, scheduling-starvation DoS, no fix planned) and CVE-2026-8805 (FX5-EIP TCP DoS).
  • CISA KEV catalog update does not add CVE-2026-1874; no confirmed in-the-wild exploitation of the disclosed MELSEC iQ-F flaws as of this date.

Sources cited for Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP

Detection coverage for TL-2026-1874

As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1874 across Splunk SPL, Microsoft KQL and Sigma, covering 2 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
2 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats