Executive Overview
Mitsubishi Electric Corporation, in coordination with CISA, has published cybersecurity advisory 2026-015 regarding CVE-2026-75890, a critical remote memory corruption and denial-of-service vulnerability affecting MELSEC iQ-F Series (FX5U, FX5UC, FX5UJ) compact programmable logic controllers (PLCs). With a CVSS v3.1 score of 9.1 (Critical), the flaw enables unauthenticated actors on the fieldbus network to crash the controller into a fatal CPU error state (CPU Error LED solid red) or manipulate active servo motion parameters.
The MELSEC iQ-F compact PLC line is deployed across automated manufacturing facilities worldwide, controlling high-precision pick-and-place robotics, semiconductor packaging machinery, automotive parts stamping lines, and automated material handling systems. A sudden controller fault immediately triggers mechanical emergency brakes, halting high-speed machinery.
Technical Dissection: Modbus Frame Length Mismatch
The vulnerability exists within the built-in Ethernet and RS-485 communication firmware module handling Modbus RTU / Modbus TCP Function Code 16 (Write Multiple Holding Registers). When an incoming frame requests a block write across register addresses, the PLC communication firmware calculates memory offsets based on the declared byte count parameter.
When an attacker submits a frame declaring a byte count that exceeds the allocated internal holding register buffer, an arithmetic comparison flaw permits an out-of-bounds heap memory overwrite into adjacent RTOS execution memory:
// Exploit Frame Structure (Modbus TCP):
// Transaction ID: 0x1337
// Protocol ID: 0x0000 (Modbus)
// Length: 0x00FC (252 bytes)
// Unit ID: 0x01
// Function Code: 0x10 (Write Multiple Registers)
// Starting Address: 0x2710 (Holding Register D10000)
// Quantity of Registers: 0x0078 (120 registers)
// Byte Count: 0xFA -> Arithmetic wrap causes heap overwrite into motion control task block!
Operational Impact on Factory Robotics & Machinery
Because MELSEC iQ-F controllers frequently drive multi-axis servo motors via high-speed pulse train outputs or SSCNET III/H optical networks, disrupting memory stability produces dangerous physical outcomes:
- Uncommanded Motion Deceleration: Corrupting servo position registers while a delta robot is handling delicate semiconductor silicon wafers causes positioning collisions, destroying tooling and silicon materials.
- Production Line Stoppage: Triggering a fatal CPU watchdog fault forces all digital outputs to OFF state, cutting power to conveyor motors and tripping upstream pneumatic feeder lines.
- Loss of Remote Maintenance Access: The PLC communication stack freezes, preventing engineering staff from connecting via GX Works3 to perform remote diagnostics until power is physically cycled.
Remediation & Defense-in-Depth Roadmap
Mitsubishi Electric has released firmware updates to remediate the vulnerability. Plant automation and cybersecurity engineers must implement the following controls:
- Update Controller Firmware: Upgrade MELSEC iQ-F FX5U and FX5UC controllers to firmware version
1.290or later, and FX5UJ to version1.050or higher. - Disable Unused Modbus Services: In the GX Works3 engineering environment, disable the Modbus TCP/RTU communication service on Ethernet and expansion boards if not explicitly required.
- Enforce IP Address Filtering: Configure the MELSEC built-in IP filter to restrict controller communication strictly to authorized HMI displays and engineering programming stations.
- Isolate Level 1 Cell Networks: Enforce strict IEC 62443-3-3 network segmentation, blocking direct routing between corporate enterprise IT networks and machine-level control buses.



