What happened
CISA released an advisory on August 27, 2026, regarding a vulnerability in Mitsubishi Electric CNC Series (Update A). The advisory, identified as ICSA-26-078-05, details a flaw that could allow a remote attacker to trigger an out-of-bounds read, resulting in a denial-of-service condition.
The affected products include several CNC models: M800VW (BND-2051W000) with firmware up to BB, M800VS (BND-2052W000) up to BB, M80V (BND-2053W000) up to BB, M80VW (BND-2054W000) up to BB, and M800W (BND-2005W000) up to FM. The vulnerability is tracked as CVE-2025-2399.
Why it matters
These CNC series are widely used in industrial automation and manufacturing. A denial-of-service vulnerability could halt production lines, leading to operational downtime and financial losses. The remote attack vector increases the severity, as attackers could exploit the flaw without physical access. Organizations using these models should review the advisory and apply any available mitigations or firmware updates to protect their systems.