SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-67560

HIGH · CVSS 7.5 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Bendix EC80 Brake ECU is susceptible to a stack-based buffer overflow that could enable an attacker to crash the ECU and execute arbitrary code remotely. This vulnerability poses a significant risk as it may compromise critical vehicle functions, including ABS, steering assist, speedometer, and shifting. Automotive manufacturers and organizations utilizing this ECU should prioritize remediation to mitigate potential safety hazards.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67560
Severity
HIGH
CVSS
7.5
EPSS
0.33%

Original NVD Description

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.