ZeroHour

CVE-2026-68967

large

Out-of-bounds Write in Bendix EC80 Brake ECU

CVSS 4.0
7.1 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-68967 is an out-of-bounds write (CWE-787) in the Bendix EC80 Brake ECU, an electronic brake control unit supplied by Bendix for heavy-duty commercial vehicles. Per the CISA ICS-CERT advisory, an attacker can trigger the flaw by delivering a crafted payload over an adjacent network — such as the vehicle's internal data bus or a connected diagnostic/telematics interface — with no privileges or user interaction required (CVSS 4.0 vector AV:A/PR:N/UI:N). Successful exploitation can establish an arbitrary write primitive in the ECU and could crash the unit; the 7.1 (High) score reflects high integrity impact, with no confidentiality impact scored. Any operator running vehicles equipped with the EC80 Brake ECU is affected; the source data does not specify affected firmware version ranges. There is currently no public proof-of-concept, no CISA KEV listing, and a low EPSS estimate (0.3% probability of exploitation in the next 30 days), indicating no known exploitation at this time.

What to do: Review the Bendix and CISA ICS-CERT advisory for the affected firmware ranges and apply the vendor's firmware update when it is published (the source data does not name fixed versions). Until patched, restrict untrusted devices from connecting to the vehicle network — e.g., exposed diagnostic connectors and third-party telematics/dongle adapters — since exploitation requires adjacent access to the ECU. Fleet operators should monitor ECU behavior and vehicle network logs for anomalies consistent with unexpected memory corruption or ECU resets.

Affected
Bendix EC80 Brake ECU
Estimated exposure
largelikely on the order of 100,000+ equipped commercial vehicles (deployment-pattern estimate) — Bendix is a major supplier of brake electronics for North American heavy-duty trucks, and the EC80 ECU is widely fitted to tractor and trailer fleets, but the source data provides no install counts, so this is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.

Weakness
CWE-787
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.