CVE-2026-13584
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN Communication Protocol are affected: Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-16 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR300-64 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-128 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-R model MXR500-256 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-N32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-8-P32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-N32 vers:all/* (CVE-2026-13584) Mitsubishi Electric MELSEC MX Controller MX-F model MXF100-16-P32 vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/local module RJ71GN11-T2 vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/local module RJ71GN11-SX vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/local module RJ71GN11-EIP vers:all/* (CVE-2026-13584) Mitsubishi Electric Master/local module FX5-CCLGN-MS vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-SX vers:all/* (CVE-2026-13584) Mitsubishi Electric CC-Link IE TSN interface board NZ81GN11-T2 vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module RD78G4 vers:all/* (CVE-2026-13584) Mitsubishi Electric Motion module RD78G8 vers:all/* (CVE-2026-13584)
CSIRTS triage
- What
- Exploitation could allow an attacker to tamper with communication data and cause a denial-of-service condition.
- Who is affected
- Mitsubishi Electric MELSEC MX Controllers MX-R models MXR300-16, MXR300-32, MXR300-64, and MXR500-128.
- Urgency
- The urgency is unknown as the severity is not specified.
- Action
- Monitor network segments for unusual activity and apply any available updates.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-13584
Get an email if CVE-2026-13584 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownMitsubishi Electric CC-Link IE TSN Communication Protocolcisa · 2026-07-30
- unknownCVE-2026-13584: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulne…nvd · 2026-07-30
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-13584)