Flaws in a truck brake control unit can knock out ABS
The US Cybersecurity and Infrastructure Security Agency published advisory ICSA-26-237-05 on 25 August 2026, covering three vulnerabilities in the Bendix EC80 Brake ECU, the control unit that runs the braking system on heavy vehicles. According to the advisory, successful exploitation could cause the loss of ABS functions, steering assist, speedometer and shifting capabilities, or disable automatic traction control. Eleven variants of the EC80ESP+ and the EC80ESP are listed as affected, and Bendix has released new firmware for all of them. CISA lists the United States and Canada as the areas of deployment, and states that no known public exploitation specifically targeting these vulnerabilities has been reported to the agency.
What happens technically
A brake ECU is a small computer that controls the braking system in a vehicle. The advisory lists eleven EC80 variants, carrying suffixes such as J1708, 2nd CAN, PLC, CAN Gateway and Integrated TPMS. The description of the most serious flaw refers to CAN traffic directly. CAN is the established standard for communication between control units in a vehicle, and it was designed without any way for the receiver to verify who sent a message. That last point is general engineering knowledge, not something the advisory states about this particular product. The advisory does not name the class of vehicle the unit belongs in either. That the Bendix EC80 is a brake controller for heavy vehicles follows from what the product is, and not from anything CISA writes. The vulnerabilities were reported to CISA by Ben Gardiner of NMFTA.
CVE-2026-67560 is a stack-based buffer overflow, meaning data is written past the end of an area the program set aside on the call stack. CISA writes that the flaw may allow an attacker to crash the ECU, and that a crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. The consequence the advisory names is the loss of the ABS function, steering assist, speedometer and shifting. The flaw is scored 7.5 in CVSS 3.1 and 7.7 in CVSS 4.0, high in both versions. The vector is the most informative part of the entry. It opens with AV:A, which places the attacker on an adjacent network rather than on the open internet, and AC:H says the attack depends on conditions the attacker does not control. The prose description in the same entry nevertheless uses the word remotely. Both statements sit in one document, they pull in opposite directions, and the advisory does not explain the difference.
The other two flaws are scored lower. CVE-2026-68967 is an out-of-bounds write, and CISA writes that a payload could establish an arbitrary write primitive and crash the ECU. It is scored 6.5 in CVSS 3.1 and 7.1 in CVSS 4.0. CVE-2026-71396 is a set of hard-coded credentials, which according to the advisory could be used to disable automatic traction control. It is scored 5.4 and 5.3. All three carry AV:A in the vector. The fixes are three new firmware versions. Units on Z228999 go to Z300822, units on Z266494 go to Z302578, and units on Z286098 go to Z302579. The advisory does not say how an attacker reaches the adjacent network, and it does not say which vehicle models carry the unit.
What this means for you if you run the fleet
If heavy vehicles are your responsibility, read closely what the advisory actually claims about the consequence. It does not say the brakes stop working. It says the functions around the brakes can fall away, meaning ABS, steering assist, the speedometer, shifting and traction control. Our assessment is that this is serious enough on its own. A driver who loses ABS in the middle of an evasive manoeuvre on a slippery road is driving a different vehicle from the one he got into. The gap between that description and «the brakes stop working» is also the gap between a news story and a scare, and you should be able to explain it when someone on the management team asks.
The second thing worth your attention is AV:A in the vector. The attacker has to be on the same local network as the ECU, and that is a very different proposition from a device exposed on the internet. Our assessment is that the question to put to your supplier is therefore who in practice gets to connect to the vehicle network. The workshop with the diagnostic tool is one answer, and the telematics box fitted after delivery is another. CISA lists the United States and Canada as the areas of deployment, and the advisory says nothing about vehicles in Norway. If you buy used tractor units from North America, or run a fleet over there, it is your problem all the same. The point that holds for any brand is that a vehicle is an OT environment on wheels, and that its firmware is updated by a workshop rather than by you.
Berigo recommends
- Find out whether your vehicles carry a Bendix EC80, and ask the workshop or the supplier to read off the firmware version. Z228999, Z266494 and Z286098 are the versions the advisory lists as affected.
- Order the upgrade to Z300822, Z302578 or Z302579 depending on the variant you have, and ask for written confirmation that it has been carried out.
- Put the vehicles into your asset inventory. A truck with software on board is an operational asset like any server, and a vulnerability you cannot locate is one you cannot close either.
- Follow the CISA guidance on network separation. Control system devices should not be reachable from the internet, they belong behind a firewall and away from the business network, and remote access should run over a more secure channel such as a VPN.
- Require your supplier to document who can connect to the vehicle network, and how diagnostics and remote access are protected. Write the answer into the supplier agreement.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch