Threat reportICS/SCADATL-2026-1874
Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876)
Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP (TL-2026-1874) is a high-severity ICS/SCADA threat scored CVSS 8.7, first published 2026-08-04. It has no confirmed attribution, affects Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module, references 4 CVEs (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876), maps to 4 MITRE ATT&CK techniques (T0814, T0822, T1190), and is covered by 9 detection rules and 2 indicators of compromise.
- CVSS
- 8.7/10High
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 2Indicators of compromise
Key facts for TL-2026-1874
- Threat ID
- TL-2026-1874
- Severity
- HIGH
- CVSS
- 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- manufacturing, critical-infrastructure, water-and-wastewater, energy, automotive, food-and-beverage
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 2
Malware and tooling in Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP
Malware and tooling: Scapy, hping3
How Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP works
Multiple remotely exploitable denial-of-service (DoS) vulnerabilities affect Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet modules and FX5-EIP EtherNet/IP modules. A remote, unauthenticated attacker can continuously send UDP packets to an exposed module, causing uncontrolled receive-buffer consumption or resource-exhaustion (CWE-670 / CWE-404) that forces the PLC network module into a DoS state from which a manual system reset is required to recover. CISA rated the flaws CVSS 4.0 8.7 (HIGH) in advisory ICSA-26-62-01; internet-facing industrial devices are the primary risk.
The Mitsubishi Electric MELSEC iQ-F Series is a widely deployed programmable logic controller (PLC) family used across manufacturing, water/wastewater, energy, and critical infrastructure. Its FX5-ENET/IP Ethernet module and FX5-EIP EtherNet/IP module expose the ODVA Common Industrial Protocol (CIP) over EtherNet/IP, which uses UDP/TCP encapsulation on port 44818 and implicit I/O messaging on UDP port 2222. CISA advisory ICSA-26-62-01 (published 2026-03-03) and Mitsubishi Electric PSIRT advisory 2025-021 disclose three related DoS vulnerabilities that share a single, trivially automatable attack vector: a remote attacker sends a continuous stream of UDP packets to the module, which the device fails to handle correctly, leading to uncontrolled receive-buffer consumption or improper resource shutdown/release. Recovery from the resulting outage requires a manual system reset of the module; the PLC process under control is disrupted in the interim.
CVE-2026-1874 (CWE-670, Always-Incorrect Control Flow Implementation) affects the FX5-ENET/IP module, firmware versions 1.106 and prior. Continuous UDP packet reception consumes the receive buffer without bound until memory is exhausted, forcing a DoS. It is fixed in firmware version 1.107 or later. CVE-2026-1875 (CWE-404, Improper Resource Shutdown or Release) affects the FX5-EIP module, versions 1.000 and prior, fixed in version 1.001 or later. CVE-2026-1876 (CWE-404) affects all versions of the FX5-ENET/IP module; as of the JVN update of 2026-04-23 the vendor has stated no patched firmware is planned for this flaw, leaving only mitigations. A closely related fourth flaw, CVE-2026-8806 (CWE-440, Expected Behavior Violation) in the FX5-ENET/IP line, also has no fix planned; technical analysis describes a real-time scheduling starvation condition in which a high-priority EtherNet/IP protocol task preempts the lower-priority internal anomaly-detection task indefinitely (a priority-inversion scenario), after which the module's internal supervisor declares the communication function unhealthy and shuts it down. On a 100 Mbps link the ratio tips at roughly 40,000 packets/sec (~27 Mbps), easily achieved from a compromised HMI or engineering workstation.
All four CVEs score CVSS 4.0 8.7 (HIGH) with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N and CVSS 3.1 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The NVD-referenced CISA-ADP SSVC assessment rates exploitation as 'none' (no confirmed in-the-wild exploitation), automatable as 'yes', and technical impact as 'partial'. CVE-2026-1874 is NOT in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the 2026-07-21 KEV update. No named threat actor has been publicly confirmed exploiting these specific CVEs; however, the adjacent ICS/OT threat landscape is directly relevant: the IRGC-affiliated CyberAv3ngers demonstrated the Unitronics internet-exposed-PLC attack playbook in AA23-335A, the FrostyGoop malware weaponized Modbus TCP/502 against 46,000+ exposed devices in Ukraine, and Forescout documented the Ramnit worm infecting legitimate Mitsubishi GX Works engineering-workstation executables. Defense therefore centers on asset exposure reduction, network segmentation, firmware patch management, and high-rate UDP/EtherNet/IP packet-rate detection.
MITRE ATT&CK techniques used in TL-2026-1874
inhibit-response-function
T0814 Denial of Service; T1691.001 Command Message
initial-access
T0822 External Remote Services
Initial Access
Affected products and versions in Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP
- Mitsubishi Electric — MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
Vulnerable versions: up to 1.106 (CVE-2026-1874); all versions (CVE-2026-1876)
Fixed in: 1.107 and later (CVE-2026-1874); no fix planned (CVE-2026-1876) - Mitsubishi Electric — MELSEC iQ-F Series FX5-EIP EtherNet/IP Module
Vulnerable versions: 1.000 and prior
Fixed in: 1.001 and later
Remediation for Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP
Patches
- Update FX5-ENET/IP firmware to version 1.107 or later (CVE-2026-1874)
- Update FX5-EIP firmware to version 1.001 or later (CVE-2026-1875)
- For CVE-2026-1876 and CVE-2026-8806 (no fix planned), migrate from FX5-ENET/IP to the successor FX5-EIP module
Immediate actions
- Remove internet exposure of FX5-ENET/IP and FX5-EIP modules; block inbound UDP/TCP port 44818 and UDP port 2222 from untrusted networks at the perimeter firewall
- Enable the module's IP filter function to restrict EtherNet/IP access to trusted hosts/IP ranges
- Place control-system networks behind firewalls and isolate them from business networks via OT network segmentation
- Monitor for and alert on high-rate UDP traffic to 44818/2222 and abnormal PLC protective-restart cycles
Workarounds
- Restrict physical access to the module and connected network equipment
- Install antivirus on engineering PCs that access the affected product
- Operate the affected product within a LAN only and block untrusted network hosts
Longer-term hardening
- Use a VPN for any remote access into the control network and keep VPN appliances patched
- Deploy ICS-aware intrusion detection (e.g., Zeek/Suricata EtherNet/IP dissectors) with packet-rate and buffer-exhaustion alerts
- Inventory and continuously manage the firmware baseline of all MELSEC iQ-F network modules
- Perform an impact/risk assessment before deploying any defensive measures, per CISA guidance
CVEs associated with Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP
Weaknesses (CWE) in Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP
Timeline of Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP
- CISA publishes ICS advisory ICSA-26-62-01; CVEs CVE-2026-1874, CVE-2026-1875, and CVE-2026-1876 are published in NVD with CVSS 4.0 8.7 (HIGH).
- Mitsubishi Electric PSIRT publishes security advisory 2025-021 detailing the affected FX5-ENET/IP and FX5-EIP modules and fixed firmware versions.
- JVN#JVNVU93286687 is updated to state that CVE-2026-1876 (FX5-ENET/IP, all versions) has no planned firmware fix, hardening the vendor's position to mitigations-only.
- NVD records for CVE-2026-1874/1875/1876 are last modified; CISA-ADP SSVC assessment confirms exploitation 'none', automatable 'yes', technical impact 'partial'.
- Mitsubishi PSIRT advisory 2026-002 discloses CVE-2026-8806 (FX5-ENET/IP all versions, scheduling-starvation DoS, no fix planned) and CVE-2026-8805 (FX5-EIP TCP DoS).
- CISA KEV catalog update does not add CVE-2026-1874; no confirmed in-the-wild exploitation of the disclosed MELSEC iQ-F flaws as of this date.
Sources cited for Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP
- CISA ICS Advisory ICSA-26-62-01 (Mitsubishi Electric MELSEC iQ-F Series)
- Mitsubishi Electric PSIRT Security Advisory 2025-021
- JVN#JVNVU93286687 (MELSEC iQ-F Series)
- NVD - CVE-2026-1874
- NVD - CVE-2026-1875
- NVD - CVE-2026-1876
- NVD - CVE-2026-8806 (FX5-ENET/IP scheduling starvation)
- System Weakness - How a Packet Flood Silences a PLC's Own Watchdog
- ODVA EtherNet/IP Developers Guide
- EtherNet/IP Encapsulation Protocol Explained
- CISA KEV Known Exploited Vulnerabilities Catalog
- CISA/NCSC AA23-335A - IRGC-affiliated cyber actors exploiting PLCs
- Mitsubishi Electric FA Download Site (firmware)
Detection coverage for TL-2026-1874
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1874 across Splunk SPL, Microsoft KQL and Sigma, covering 2 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.