SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.
USACybersecurityE/E Architecture

CISA flagged three flaws in Bendix brake ECUs that can cut ABS and steering assist

A US federal advisory said a stack overflow in Bendix's EC80 commercial-vehicle brake controller can be used to run code and inject CAN traffic, and named replacement firmware for all eleven affected part numbers.

The US Cybersecurity and Infrastructure Security Agency published an advisory on August 25 describing three vulnerabilities in Bendix Commercial Vehicle Systems’ EC80 anti-lock brake controllers. The revision history recorded it as an initial publication.

The most serious, CVE-2026-67560, is a stack-based buffer overflow rated 7.5 under CVSS v3.1 and 7.7 under v4.0, exploitable from an adjacent network. CISA said the flaw crashes the controller, after which a crafted payload can execute code remotely or inject arbitrary traffic onto the vehicle’s CAN network, causing the loss of anti-lock braking, steering assist, the speedometer and gear shifting. A second flaw, CVE-2026-68967, is an out-of-bounds write rated 6.5 and 7.1. The third, CVE-2026-71396, covers hard-coded credentials rated 5.4 and 5.3, which CISA said can be used to disable automatic traction control.

Eleven part numbers are affected across three firmware baselines. Bendix has published replacements for each: Z228999 moves to Z300822, Z266494 to Z302578 and Z286098 to Z302579. The controllers are deployed in the United States and Canada.

The vulnerabilities were reported to CISA by Ben Gardiner of the National Motor Freight Traffic Association. CISA said it knew of no public exploitation targeting the flaws.

Why it mattersA brake controller that can be made to accept injected network traffic moves vehicle cybersecurity from data exposure to loss of a safety function.

Source: CISA

The SDV Sector Brief

The month in vehicle software — top stories, what our readers read most, and an editor's take. First Tuesday of the month, 08:30 CET. Double opt-in, unsubscribe anytime.