Skip to main content
Security

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

Promo/Hero Graphic Image: Primary
Exploiting Volvo/Eicher's fleet management platform to gain control over all users and vehicles. The vulnerability was discovered in the APIs of My Eicher, a fleet management system built by VE Commercial Vehicles, a joint venture between the Volvo Group and Eicher Motors. The flaw allowed access to unauthenticated internal/admin APIs, enabling account takeover and control over fleets of hundreds of vehicles. As of November 2024, 275k vehicles and 115k customers were registered, though later data showed 676k vehicles and 748k customers. The vulnerability was reported to VECV in November 2025 and fixed by November 20, 2025, before being publicly disclosed on July 27, 2026.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from eaton-works.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Microsoft fixes 974 flaws, including two exploited Windows zero-days

Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppCont...

Security
Security

N-able issues hotfix for N-central zero-day

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...

Security
Security

Chrome 153 fixes actively exploited V8 flaw

Google released Chrome 153 to the stable channel with fixes for 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write flaw in the V8 JavaScript and WebAssembly engine. Google says an exploit for the medium-severity...

Security
Security

CISA adds exploited Chromium V8 flaw to KEV catalog

CISA has added CVE-2026-85046, a Chromium V8 type-confusion vulnerability, to its Known Exploited Vulnerabilities catalog, saying it is actively exploited. The flaw can be triggered when a target loads a specially crafted HTML pag...