CISA Issues Urgent Advisory: Two Critical Vulnerabilities in Bendix EC80 Brake ECU
Stack-based buffer overflow and out-of-bounds write flaws could compromise vehicle safety systems
Key Takeaways
- CISA issued advisory ICSA-26-237-05 on August 25, 2026, regarding two critical vulnerabilities in Bendix EC80 Brake ECU.
- CVE-2026-67560 (CVSS 7.5) is a stack-based buffer overflow that could allow arbitrary code execution or CAN bus traffic injection.
- CVE-2026-68967 (CVSS 7.7) is an out-of-bounds write vulnerability that could establish an arbitrary write primitive.
- Affected firmware revisions are identified by part numbers Z228999, Z266494, and Z286098.
- Bendix recommends updating firmware to Z300822, Z302578, or Z302579 depending on the specific product version.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


