CVE-2026-1876Disclosure(mitsubishielectric / melsec_iq-f_fx5-enet\/ip)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch mitsubishielectric melsec_iq-f_fx5-enet\/ip systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. A system reset of the product is required for recovery.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • melsec_iq-f_fx5-enet\/ip
  • melsec_iq-f_fx5-enet\/ip_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
melsec_iq-f_fx5-enet\/ipmelsec_iq-f_fx5-enet\/ip_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-03: 3Mentions · 2026-06-19: 1Active Exploitation · 2026-06-19: 1Patch / Workaround · 2026-06-19: 1Technical Details · 2026-03-03: 3Technical Details · 2026-06-19: 103-0306-19
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-033
Disclosure3
2026-06-191
Active Exploitation1
Full discourse4 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are exploiting CVE-2026-1876 to render Mitsubishi Electric's MELSEC iQ-F Series modules unresponsive through UDP packet floods. This DoS vulnerability affects all versions of the FX5-ENET/IP module, requiring system resets to restore functionality. #IndustrialSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/mitsubishi-electric-melsec-iq-f-series-fx5-enet-ip-ethernet-module-cve-2026-1876

    Post summary

    The post reports that attackers are actively exploiting CVE‑2026‑1876 to cause a denial‑of‑service on Mitsubishi Electric MELSEC iQ‑F series modules, with recovery only possible after system resets.

    00000134
    1.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1876 Mitsubishi MELSEC iQ-F FX5-ENET/IP UDP Packet Denial-of-Service Vulnerabi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1876 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new Denial‑of‑Service vulnerability (CVE‑2026‑1876) affecting Mitsubishi MELSEC iQ‑F FX5‑ENET/IP has been announced, with links to vulnerability details and a notification, but no PoC, exploit, or patch information is provided.

    0000051
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1876 Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a … https://www.cve.org/CVERecord?id=CVE-2026-1876 ----- Traducción: CVE-2026-1876 Vul… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑1876, an Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric’s MELSEC iQ‑F Series FX5‑ENET/IP Ethernet Module, linking to the CVE record but providing no further exploitation or mitigation details.

    0000038
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1876 Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a … https://www.cve.org/CVERecord?id=CVE-2026-1876

    Post summary

    The text announces CVE-2026-1876, an Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric’s FX5‑ENET/IP Ethernet Module, but offers no PoC, exploit, or mitigation details.

    00000324
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWmitsubishielectricmelsec_iq-f_fx5-enet\/ip---
OSmitsubishielectricmelsec_iq-f_fx5-enet\/ip_firmware---

Explore more