CISA Advisory: Multiple Vulnerabilities in Bendix EC80 Brake ECU
CISA released an advisory on August 25, 2026, detailing three vulnerabilities in the Bendix EC80 Brake ECU, a component used in commercial vehicle braking systems. The vulnerabilities are: CVE-2026-67560 (stack-based buffer overflow, CVSS 7.5), CVE-2026-68967 (out-of-bounds write, CVSS 6.5), and CVE-2026-71396 (use of hard-coded credentials, CVSS 5.4). Successful exploitation could allow an attacker to crash the ECU, execute arbitrary code, inject arbitrary CAN bus traffic, or disable safety functions such as ABS, steering assist, speedometer, shifting, and automatic traction control. The affected products include multiple versions of the EC80ESP and EC80ESP+ series. Bendix has provided firmware updates for each affected version. CISA recommends users apply the updates and follow defensive measures to minimize risk. No public exploitation has been reported at the time of publication.
What we know
The vulnerabilities could allow an attacker to crash the ECU, execute arbitrary code, inject CAN bus traffic, or disable ABS, steering assist, speedometer, shifting, and automatic traction control.
▤ 1 sources›
Three vulnerabilities were disclosed: CVE-2026-67560 (stack-based buffer overflow), CVE-2026-68967 (out-of-bounds write), and CVE-2026-71396 (hard-coded credentials).
▤ 1 sources›
No known public exploitation has been reported to CISA at the time of publication.
▤ 1 sources›
Affected products include multiple versions of Bendix EC80ESP and EC80ESP+ series.
▤ 1 sources›
CISA published an advisory on 2026-08-25 regarding Bendix EC80 Brake ECU.
▤ 1 sources›
Bendix has released firmware updates for all affected versions.
▤ 1 sources›
Open any source to inspect its original language, when DoseFix received it, and the claims it supports.
Bendix EC80 Brake ECU
cisa.gov · EN · Published · ReceivedLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.