Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876) — Threadlinqs Intelligence
As of 2026-08-04, Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876) is a high-severity ics scada threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 2 indicators of compromise.
Threat ID: TL-2026-1874 · Severity: HIGH · CVSS: 8.7 · Status: ACTIVE · Category: ICS_SCADA
Multiple remotely exploitable denial-of-service (DoS) vulnerabilities affect Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet modules and FX5-EIP EtherNet/IP modules. A remote,
The Mitsubishi Electric MELSEC iQ-F Series is a widely deployed programmable logic controller (PLC) family used across manufacturing, water/wastewater, energy, and critical infrastructure. Its FX5-ENET/IP Ethernet module and FX5-EIP EtherNet/IP module expose the ODVA Common Industrial Protocol (CIP) over EtherNet/IP, which uses UDP/TCP encapsulation on port 44818 and implicit I/O messaging on UDP port 2222. CISA advisory ICSA-26-62-01 (published 2026-03-03) and Mitsubishi Electric PSIRT advisory 2025-021 disclose three related DoS vulnerabilities that share a single, trivially automatable attack vector: a remote attacker sends a continuous stream of UDP packets to the module, which the device fails to handle correctly, leading to uncontrolled receive-buffer consumption or improper resource shutdown/release. Recovery from the resulting outage requires a manual system reset of the module; the PLC process under control is disrupted in the interim.
CVE-2026-1874 (CWE-670, Always-Incorrect Control Flow Implementation) affects the FX5-ENET/IP module, firmware versions 1.106 and prior. Continuous UDP packet reception consumes the receive buffer without bound until memory is exhausted, forcing a DoS. It is fixed in firmware version 1.107 or later. CVE-2026-1875 (CWE-404, Improper Resource Shutdown or Release) affects the FX5-EIP module, versions 1.000 and prior, fixed in version 1.001 or later. CVE-2026-1876 (CWE-404) affects all versions of the FX5-ENET/IP module; as of the JVN update of 2026-04-23 the vendor has stated no patched firmware is planned for this flaw, leaving only mitigations. A closely related fourth flaw, CVE-2026-8806 (CWE-440, Expected Behavior Violation) in the FX5-ENET/IP line, also has no fix planned; technical analysis describes a real-time scheduling starvation condition in which a high-priority EtherNet/IP protocol task preempts the lower-priority internal anomaly-detection task indefinitely (a priority-inversion scenario), after which the module's internal supervisor declares the communication function unhealthy and shuts it down. On a 100 Mbps link the ratio tips at roughly 40,000 packets/sec (~27 Mbps), easily achieved from a compromised HMI or engineering workstation.
All four CVEs score CVSS 4.0 8.7 (HIGH) with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N and CVSS 3.1 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The NVD-referenced CISA-ADP SSVC assessment rates exploitation as 'none' (no confirmed in-the-wild exploitation), automatable as 'yes', and technical impact as 'partial'. CVE-2026-1874 is NOT in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the 2026-07-21 KEV update. No named threat actor has been publicly confirmed exploiting these specific CVEs; however, the adjacent ICS/OT threat landscape is directly relevant: the IRGC-affiliated CyberAv3ngers demonstrated the Unitronics internet-exposed-PLC attack playbook in AA23-335A, the FrostyGoop malware weaponized Modbus TCP/502 against 46,000+ exposed devices in Ukraine, and Forescout documented the Ramnit worm infecting legitimate Mitsubishi GX Works engineering-workstation executables. Defense therefore centers on asset exposure reduction, network segmentation, firmware patch management, and high-rate UDP/EtherNet/IP packet-rate detection.
Weaknesses (CWE)
CWE-670, CWE-404
Target sectors: manufacturing, critical-infrastructure, water-and-wastewater, energy, automotive, food-and-beverage
Target regions: Global
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 2 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ICS_SCADA, HIGH, threat intelligence, cybersecurity, CVE-2026-1874, CVE-2026-1875, CVE-2026-1876, T1190, T1691.001, T0814, T0822