Answer in brief
CVE-2026-67560 records a Unknown severity vulnerability in Stack-based Buffer Overflow in Bendix EC80 Brake ECU. The current sources do not mark it as known exploited. The current feed maps Bendix/EC80ESP 2nd CAN (generic), Bendix/EC80ESP+ 2nd CAN (generic), Bendix/EC80ESP 4S/4M (generic), Bendix/EC80ESP 6S/6M (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Bendix/EC80ESP 2nd CAN (generic), Bendix/EC80ESP+ 2nd CAN (generic), Bendix/EC80ESP 4S/4M (generic), Bendix/EC80ESP 6S/6M (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Bendix/EC80ESP 2nd CANgeneric | Z266494 | Not reported |
| Bendix/EC80ESP+ 2nd CANgeneric | Z228999 | Not reported |
| Bendix/EC80ESP 4S/4Mgeneric | Z286098 | Not reported |
| Bendix/EC80ESP 6S/6Mgeneric | Z266494 | Not reported |
| Bendix/EC80ESP+ 6S/6Mgeneric | Z228999 | Not reported |
| Bendix/EC80ESP CAN Gatewaygeneric | Z266494 | Not reported |
| Bendix/EC80ESP+ Integrated TPMSgeneric | Z228999 | Not reported |
| Bendix/EC80ESP+ J1708generic | Z228999 | Not reported |
| Bendix/EC80ESP PLCgeneric | Z266494 | Not reported |
| Bendix/EC80ESP PLCgeneric | Z286098 | Not reported |
| Bendix/EC80ESP+ PLCgeneric | Z228999 | Not reported |
Published upstream
Aug 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 27, 2026
Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.
Quoted source text, attributed separately from HOL analysis.