CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Acrisure KARR BT and DR-100

criticalCVE-2026-18411
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware <July_20_2026 DR-100 firmware <July_20_2026 CVSS Vendor Equipment Vulnerabilities v3 8.1 Acrisure Acrisure KARR BT and DR-100 Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-18411 The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization. View CVE Details Affected Products Acrisure KARR BT and DR-100 Vendor: Acrisure Product Version: Acrisure KARR BT firmware: <July_20_2026, Acrisure DR-100 firmware: <July_20_2026 Product Status: known_affected Remediations Vendor fix Acrisure Protection Group released a firmware update on July 20, 2026, to address this vulnerability. They recommend that affected users should follow the directions found here: https://www.karrsecurity.com/karr-security-firmware-update-instructions. https://www.karrsecurity.com/karr-security-firmware-update-instructions Relevant CWE: CWE-321 Use of Hard-coded Cryptographic Key Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H 4.0 7.2 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Aaron Schulman, Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff, Nishant Bhaskar of UC San Diego team reported this vulnerability to CISA. Legal Notice and Terms of Use This product is prov

CSIRTS triage

vendor: Thermo Fisher Applied Biosystemsproduct: Genetic AnalyzersOtheraffected: 3500/3500xL <=4.0.2, 3730/3730xL <=5.0.2, SeqStudio <=1.2.5, SeqStudio Flex <=1.2.0, GeneMapper ID-X <=v1.7.3, 3130 <=4.1, 3100/3100-Avant <=2.0, 310 <=3.1
What
Vulnerability allowing modification of output files (.fsa/.hid) and tampering with DNA test data results.
Who is affected
Deployments of Applied Biosystems genetic analyzer software across multiple product lines and versions as specified.
Urgency
Patch immediately as data tampering in genetic analysis results poses critical risk to diagnostic integrity and patient care.
Action
Update all affected genetic analyzer software to the latest patched versions as specified in the advisory.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Genetic Analyzers

Get an email when a new Genetic Analyzers advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-04
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-216-01

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-18411coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories