CVE-2026-68967: Bendix EC80ESP+ 2nd Can
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.
Affected products
- Bendix EC80ESP+ 2nd Can: version Z228999 only
- Bendix EC80ESP+ 6s/6m: version Z228999 only
- Bendix EC80ESP+ Integrated Tpms: version Z228999 only
- Bendix EC80ESP+ j1708: version Z228999 only
- Bendix EC80ESP+ PLC: version Z228999 only
- Bendix EC80ESP 2nd Can: version Z266494 only
- Bendix EC80ESP 4s/4m: version Z286098 only
- Bendix EC80ESP 6s/6m: version Z266494 only
- Bendix EC80ESP Can Gateway: version Z266494 only
- Bendix EC80ESP PLC: version Z266494 only; version Z286098 only
Published 2026-08-28. Last modified 2026-09-03.