CVE-2026-68967
largeOut-of-bounds Write in Bendix EC80 Brake ECU
CVE-2026-68967 is an out-of-bounds write (CWE-787) in the Bendix EC80 Brake ECU, an electronic brake control unit supplied by Bendix for heavy-duty commercial vehicles. Per the CISA ICS-CERT advisory, an attacker can trigger the flaw by delivering a crafted payload over an adjacent network — such as the vehicle's internal data bus or a connected diagnostic/telematics interface — with no privileges or user interaction required (CVSS 4.0 vector AV:A/PR:N/UI:N). Successful exploitation can establish an arbitrary write primitive in the ECU and could crash the unit; the 7.1 (High) score reflects high integrity impact, with no confidentiality impact scored. Any operator running vehicles equipped with the EC80 Brake ECU is affected; the source data does not specify affected firmware version ranges. There is currently no public proof-of-concept, no CISA KEV listing, and a low EPSS estimate (0.3% probability of exploitation in the next 30 days), indicating no known exploitation at this time.
What to do: Review the Bendix and CISA ICS-CERT advisory for the affected firmware ranges and apply the vendor's firmware update when it is published (the source data does not name fixed versions). Until patched, restrict untrusted devices from connecting to the vehicle network — e.g., exposed diagnostic connectors and third-party telematics/dongle adapters — since exploitation requires adjacent access to the ECU. Fleet operators should monitor ECU behavior and vehicle network logs for anomalies consistent with unexpected memory corruption or ECU resets.
| Bendix EC80 Brake ECU | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.
- Weakness
- CWE-787
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.