VDB
ICSA-26-181-01
ICSA-26-181-01
PUBLISHED
CVSS 5 MEDIUM
Successful exploitation of these vulnerabilities could allow a local attacker to tamper with or destroy information in the affected product, cause a denial-of-service condition in the affected product, or execute arbitrary code when a specially crafted archive file is decompressed by the 7-Zip component included in MELSOFT Update Manager.
Risk Scores
CVSS 3.1
5
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M: >=1.000A|<=1.014Q |
Timeline
- Jun 30, 2026 CVE Published
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-01.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-01 advisory
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf url
- https://www.cisa.gov/uscert/ncas/tips/ST04-014 url
- https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01 url
- https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b url
- https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing url
- https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks url
- https://www.mitsubishielectric.co.jp/fa/download/index.html fix
- https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-004_en.pdf fix