CISA Issues Urgent Advisory: Two Critical Vulnerabilities in Bendix EC80 Brake ECU
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent industrial control systems advisory (ICSA-26-237-05) detailing two critical vulnerabilities affecting the Bendix EC80 Brake ECU. The flaws, tracked as CVE-2026-67560 and CVE-2026-68967, have CVSS scores of 7.5 and 7.7 respectively. Successful exploitation could allow attackers to crash the electronic control unit, remotely execute arbitrary code, or inject arbitrary Controller Area Network (CAN) bus traffic, potentially disabling critical safety functions including Anti-lock Braking System (ABS), steering assist, speedometer, and shifting capabilities in commercial vehicles. The advisory covers multiple firmware revisions identified by part numbers Z228999, Z266494, and Z286098.