<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>GX Works3 (All Versions) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gx-works3-all-versions/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 17:11:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gx-works3-all-versions/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass Vulnerability in Mitsubishi Electric GX Works3</title><link>https://feed.craftedsignal.io/briefs/2026-09-mitsubishi-authentication-bypass/</link><pubDate>Thu, 17 Sep 2026 17:11:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mitsubishi-authentication-bypass/</guid><description>An incorrect implementation of the authentication algorithm (CVE-2026-15688) in Mitsubishi Electric GX Works3 and Motion Control Settings allows local attackers to bypass block password protections and manipulate control programs.</description><content:encoded><![CDATA[<p>Mitsubishi Electric GX Works3 and the bundled Motion Control Settings software are affected by an authentication algorithm flaw (CVE-2026-15688), classified as CWE-303. This vulnerability stems from an incorrect implementation that allows a local user to bypass security controls. By executing the application and performing memory manipulation to alter parts of the loaded executable module, an attacker can circumvent password validation mechanisms. Successful exploitation grants the attacker the ability to view, tamper with, destroy, or delete critical control programs used in industrial manufacturing environments. Given the potential impact on control logic, the vulnerability is highly critical in operational technology (OT) settings where integrity of control programs is essential for safety and uptime.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects users of Mitsubishi Electric GX Works3 and Motion Control Settings worldwide, particularly within the critical manufacturing sector. Successful exploitation leads to total loss of integrity and availability of control programs, potentially resulting in unauthorized process modification or operational disruption. The vulnerability is assigned a CVSS v3.1 score of 8.8 (High) and a CVSS v4.0 score of 9.2 (Critical).</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update Mitsubishi Electric GX Works3 to version 1.096A or later to address CVE-2026-15688.</li>
<li>Update Motion Control Settings to version 1.070Y or later.</li>
<li>Following the update, configure the security version for projects to &quot;2&quot; as detailed in the Mitsubishi Electric security manual.</li>
<li>Restrict local physical access to workstations running the affected software and implement rigorous access controls for all users who interact with these machines.</li>
<li>Deploy endpoint security solutions to monitor for suspicious process injection or memory modification attempts on engineering workstations.</li>
<li>Isolate control system networks from untrusted networks and the internet, ensuring remote access is restricted to authenticated, VPN-secured connections.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>industrial-control-systems</category><category>cve</category><category>authentication-bypass</category></item></channel></rss>