← Back to Feed

Acrisure KARR BT and DR-100

CVE-2026-18411

August 4, 2026 · CISA (US-CERT) · Severity: CRITICAL

A hard-coded cryptographic key vulnerability in Acrisure KARR BT and DR-100 automotive anti-theft systems allows attackers within Bluetooth range to issue unauthorized commands. This could enable door unlocking and engine immobilization. Acrisure released a firmware update on July 20, 2026 to remediate the issue.

Key Takeaways

  • Use of a hard-coded Bluetooth authentication key allows unauthorized vehicle control commands.
  • Attackers within Bluetooth range can unlock doors or immobilize the engine.
  • A firmware update was released on July 20, 2026 to address the vulnerability.
☕ Buy a Coffee