CISA updated advisories for Mitsubishi Electric Iconics Digital Solutions and related Mitsubishi products after disclosure of a high-severity malicious code execution vulnerability in the Phone agent used by the multi-agent notification feature. The flaw is an uncontrolled search path element issue tracked as CWE-427 and affects GENESIS64, ICONICS Suite, MC Works64, GENESIS32, and Hyper Historian. According to the advisory, all versions of MC Works64 and GENESIS32 are impacted, while GENESIS64, ICONICS Suite, and Hyper Historian are affected through version 10.97.3; CISA also referenced related updates covering Mitsubishi HMI/SCADA deployments.
Exposure depends on whether the multi-agent notification feature and Phone agent are installed and, in some cases, whether a Dialogic telephony board driver is present. Mitsubishi said a fix is available in version 10.98 or later for some environments that do not require the Phone agent, but no fix is planned for MC Works64, GENESIS32, or certain Phone agent use cases. CISA and Mitsubishi recommended removing the multi-agent notification feature if it is not needed, avoiding Phone agent installation during custom setup, installing the Dialogic driver where applicable, and tightening network segmentation, remote access, email handling, and physical access controls. The vulnerability carries a CVSS v3.1 score of 7.8.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
On April 7, 2026, CISA published updated versions of advisories ICSA-24-184-03 and ICSA-24-338-04, reflecting continued maintenance of guidance for the Mitsubishi Electric and ICONICS vulnerabilities. The updates indicate the advisories remained active and were revised after their original publication.
Mitsubishi stated that version 10.98 or later fixes the issue for some GENESIS64, ICONICS Suite, and Hyper Historian users who do not require the Phone agent. It also said no fix is planned for MC Works64, GENESIS32, or certain Phone agent use cases, recommending uninstalling or avoiding the vulnerable feature and applying compensating controls.
Mitsubishi Electric released PSIRT advisory 2025-018 for the vulnerability affecting its products and Mitsubishi Electric Iconics Digital Solutions software. The vendor advisory documented impacted products and remediation or mitigation guidance.
CISA disclosed a high-severity uncontrolled search path vulnerability affecting the Phone agent in Mitsubishi Electric and ICONICS products including GENESIS64, ICONICS Suite, MC Works64, GENESIS32, and Hyper Historian. The advisory described affected versions, exploitation conditions, and mitigations.
CISA published advisory ICSA-24-184-03 concerning Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric products. The advisory was later updated, indicating continued tracking of the affected products and vulnerabilities.
CISA issued advisory ICSA-22-020-01 covering Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA products. This marks the earliest referenced public disclosure in the provided materials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourcemitsubishielectric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.