Government Advisory

Mitsubishi Electric Industrial Devices Vulnerable to Denial-of-Service Attacks

CISA · 27 Aug 2026
Key Takeaway If your business uses industrial control or automation equipment, check with your vendor or IT provider to confirm whether your devices are affected and apply recommended security patches or network protections promptly.

CISA has issued an updated advisory covering a security flaw affecting multiple Mitsubishi Electric CC-Link IE TSN Remote I/O modules, including several NZ2GN2S1 and NZ2GN2B1 series products running affected firmware versions. The vulnerability could allow a remote attacker to send a specially crafted UDP packet to the device, potentially causing a denial-of-service condition, a timeout error, or a communication delay.

These modules are used in industrial automation and manufacturing environments, where any disruption to network communication can halt production lines or interfere with equipment monitoring and control. While this advisory is most directly relevant to organisations using industrial control systems (ICS) or operational technology (OT), it's a useful reminder for all businesses that internet-connected industrial equipment can be a target for attackers, not just office IT systems.

Businesses using any of the affected Mitsubishi Electric modules should consult the official CISA advisory and Mitsubishi Electric's guidance for patches or mitigation steps, such as network segmentation and restricting access to these devices from untrusted networks.

ICS OT Security Mitsubishi Electric Denial of Service CISA Advisory

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.