Cyber Resilience
← All news
Confirmed

Mitsubishi Electric CNC Series (Update A)

Our takeCISA reports active exploitation of an out-of-bounds read in Mitsubishi Electric M800VW and M800VS CNC systems that can cause denial of service. Update immediately if you operate the affected versions.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of CVE-2025-2399 in Mitsubishi Electric M800VW (<=BB) and M800VS CNC series. Successful attacks can cause an out-of-bounds read leading to denial-of-service. Update immediately if you operate affected versions.
What this means for you — Lean IT orgs:If you run Mitsubishi Electric CNC machines (M800VW or M800VS series), check the version and apply the update right away. This flaw lets a remote attacker crash the controller.
What this means for you — MSP:Check client environments for Mitsubishi Electric M800VW (<=BB) or M800VS CNC controllers and apply the vendor update. This is an actively exploited remote DoS vulnerability.
What this means for you — Researcher:CISA added CVE-2025-2399 (out-of-bounds read leading to DoS) in Mitsubishi Electric CNC M800VW (<=BB) and M800VS to its Known Exploited Vulnerabilities catalog.