A TSN Protocol Flaw With No Fix Now Covers Eight More Mitsubishi Products
Update A to ICSA-26-211-07 adds eight part numbers to a CC-Link IE TSN message-integrity flaw that affects every firmware version and will not be patched.

CISA re-issued ICSA-26-211-07 as Update A on 17 September, expanding the list of Mitsubishi Electric products affected by CVE-2026-13584 — a CWE-924 weakness, improper enforcement of message integrity during transmission in a communication channel, in the CC-Link IE TSN protocol.
The score is 7.1 high on both CVSS v3.1 and v4.0, with adjacent network access required. An attacker on the same network can tamper with communication data by sending specially crafted packets under specific timing conditions, producing denial of service or incorrect operation of the device.
Update A adds MXF100S-N32, MXF100S-P32, MXF100S-8-N32, MXF100S-8-P32, MXF100S-16-N32, MXF100S-16-P32, LD78G4 and LD78G16, and removes MI2532-W, MI2332-W and NZ2GACP610-60. More than 80 Mitsubishi products use the protocol, across MELSEC controllers, motion modules, servo drives, industrial robots, inverters, GOT3000 HMIs, communication modules and SDKs. Every version is listed as affected.
There is no fix planned. This is a protocol-level weakness, not an implementation bug in one product, and the vendor's guidance is entirely physical and network-based: restrict site access, isolate behind firewalls, deploy only on trusted networks, and lock the Ethernet ports — Mitsubishi explicitly mentions port lock accessories, which is an unusual thing to find in a CISA advisory and a reasonable indication of how the risk is meant to be managed.
For plant engineers the useful part of Update A is the parts list. Eight more numbers to search for in an asset inventory, on a deterministic Ethernet fabric that is widely deployed on factory floors and cannot be patched out of the problem.