CVE-2026-15688 is a high-severity authentication bypass vulnerability affecting Mitsubishi Electric GX Works3 and the bundled Motion Control Settings software, across all versions. Assigned a CVSS v3 score of 8.8, the flaw stems from an incorrect implementation of an authentication algorithm that allows a local attacker to authenticate successfully using an invalid block password by manipulating executable memory at runtime.
CISA published an ICS advisory on 17 September 2026, classifying the affected product under the Critical Manufacturing critical infrastructure sector. All deployed versions worldwide are confirmed affected. At the time of advisory publication, no public exploit code had been identified, though the nature of the vulnerability means that an attacker with local access to an engineering workstation running GX Works3 could view, tamper with, destroy, or delete control programs without legitimate credentials.
The vulnerability is particularly significant given GX Works3's role as a programmable logic controller (PLC) engineering environment used in industrial automation globally. Successful exploitation could give an attacker direct control over operational technology (OT) processes, with potential consequences ranging from production disruption to physical process manipulation.
Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.
We use analytics cookies to understand how visitors use Deltabridge and improve the site. They’re off until you accept. See our Privacy Policy.