CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68967

criticalcovered by 1 sourcefirst seen 2026-08-25
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control. The following versions of Bendix EC80 Brake ECU are affected: EC80ESP+ J1708 Z228999 EC80ESP+ 6S/6M Z228999 EC80ESP+ PLC Z228999 EC80ESP+ 2nd CAN Z228999 EC80ESP+ Integrated TPMS Z228999 EC80ESP 6S/6M Z266494 EC80ESP PLC Z266494 EC80ESP 2nd CAN Z266494 EC80ESP CAN Gateway Z266494 EC80ESP 4S/4M Z286098 EC80ESP PLC Z286098 CVSS Vendor Equipment Vulnerabilities v3 7.5 Bendix Bendix EC80 Brake ECU Stack-based Buffer Overflow, Out-of-bounds Write, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: United States, Canada Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-67560 The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting. View CVE Details Affected Products Bendix EC80 Brake ECU Vendor: Bendix Product Version: Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098 Product Status: known_affected Remediations Mitigation Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. mailto:info@Bendix.com Vendor fix EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822. Ve

CSIRTS triage

vendor: Bendixproduct: Bendix EC80 Brake ECUMemory corruptionMisconfigurationaffected: Multiple (Z228999, Z266494, Z286098)
What
Bendix EC80 Brake ECU firmware contains stack-based buffer overflow and hard-coded credential vulnerabilities affecting brake and traction control systems.
Who is affected
Multiple Bendix EC80 ECU variants in heavy vehicles across North America.
Urgency
Critical; memory corruption in brake control firmware can disable ABS, steering assist, and traction control, creating severe vehicle safety hazards.
Action
Contact Bendix for firmware updates addressing stack overflow and credential hardening in EC80 variants.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-68967

Get an email if CVE-2026-68967 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-68967

CVE.org record

Embed the live status

CVE-2026-68967 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68967 status](https://www.csirts.com/badge/CVE-2026-68967)](https://www.csirts.com/cve/CVE-2026-68967)