Cyber Resilience
← All news
Confirmed

Mitsubishi Electric CNC Series (Update A)

Our takeCISA reports active exploitation of an out-of-bounds read in Mitsubishi Electric M800VW and M800VS CNC systems that can cause denial of service. Update immediately if you operate the affected versions.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of an out-of-bounds read (CVE-2025-2399) in Mitsubishi Electric M800VW (<=BB) and M800VS CNC systems that can be triggered remotely to cause denial of service. Update immediately or segment/isolate affected CNC controllers if you operate them.
What this means for you — Lean IT orgs:If you run Mitsubishi Electric M800VW or M800VS CNC machines, update the firmware right away. This flaw lets a remote attacker crash the system; check with your machine vendor or integrator if you are unsure how to patch.
What this means for you — MSP:Audit client environments for any Mitsubishi Electric M800VW (<=BB) or M800VS CNC deployments and apply the vendor update immediately. Most clients will be unaffected unless they operate industrial automation equipment.
What this means for you — Researcher:CISA confirms active exploitation of CVE-2025-2399 (out-of-bounds read leading to DoS) in Mitsubishi Electric M800VW and M800VS CNC Series. See the updated ICSA-26-078-05 advisory for affected part numbers and mitigations.