Junglewise Threat Intelligence

CVE-2026-68967: Bendix EC80 Brake ECU out-of-bounds write

CVE-2026-68967 · Severity: medium · CVSS 6.5 · Published 2026-08-28

Technologies: Bendix EC80 Brake ECU. Vendors: Bendix.

Executive brief

The Bendix EC80 Brake ECU is an embedded control unit that manages critical braking functions in commercial vehicles, including ABS, steering assist, and traction control. An attacker who exploits this out-of-bounds write vulnerability could crash the ECU or establish arbitrary write capabilities, potentially disabling braking and safety systems and creating a severe safety hazard.

Technical details

This vulnerability is an out-of-bounds write flaw in the Bendix EC80 Brake ECU firmware that allows an attacker to write data beyond allocated memory boundaries. A crafted CAN bus payload delivered to the device could be used to establish an arbitrary write primitive, enabling code execution, memory corruption, or system crash. The attack vector is adjacent network (CAN bus) with no authentication required, though physical access to the vehicle is typically needed to inject CAN messages. Successful exploitation could crash the ECU and disable critical safety functions including ABS, steering assist, speedometer, and traction control. Firmware patches are available from Bendix—affected Z228999 versions should update to Z300822, Z266494 versions to Z302578, and Z286098 versions to Z302579.

Affected products

  • Bendix EC80 Brake ECU EC80ESP+ J1708 Z228999, EC80ESP+ 6S/6M Z228999, EC80ESP+ PLC Z228999, EC80ESP+ 2nd CAN Z228999, EC80ESP+ Integrated TPMS Z228999, EC80ESP 6S/6M Z266494, EC80ESP PLC Z266494, EC80ESP 2nd CAN Z266494, EC80ESP CAN Gateway Z266494, EC80ESP 4S/4M Z286098, EC80ESP PLC Z286098

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: advisory: CISA ICSA-26-237-05 advisory published

References

Related threats