Government Advisory

Security Flaw Found in Mitsubishi Electric CNC Machine Controllers

CISA · 27 Aug 2026
Key Takeaway If your business uses industrial control equipment like CNC machines, check with your equipment vendor for security updates and ensure these systems are isolated from general business networks and the internet.

The US Cybersecurity and Infrastructure Security Agency (CISA) has updated an advisory concerning a vulnerability affecting numerous Mitsubishi Electric CNC (Computer Numerical Control) Series products. Tracked as CVE-2025-2399, the flaw could allow a remote attacker to trigger an out-of-bounds read, causing a denial-of-service condition that disrupts the affected equipment's operation.

The vulnerability impacts a wide range of Mitsubishi Electric CNC controller models, including the M800, M80, E80, C80 and M700-series families, spanning multiple firmware versions. These controllers are commonly used in industrial and manufacturing environments to control precision machining equipment, meaning a successful attack could halt production lines or damage business operations reliant on this equipment.

While CNC systems are typically found in manufacturing and industrial settings rather than typical office environments, Australian small businesses that operate machine shops, fabrication facilities, or rely on third-party manufacturers using this equipment should be aware of the risk. Organisations using affected devices should consult Mitsubishi Electric and CISA's official advisory for patching guidance and recommended network segmentation practices to reduce exposure.

ICS Security CISA Advisory Manufacturing Denial of Service Mitsubishi Electric

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.