← Back to Feed
Acrisure KARR BT and DR-100
CVE-2026-18411
August 4, 2026 · CISA (US-CERT) · Severity: CRITICAL
A hard-coded cryptographic key vulnerability in Acrisure KARR BT and DR-100 automotive anti-theft systems allows attackers within Bluetooth range to issue unauthorized commands. This could enable door unlocking and engine immobilization. Acrisure released a firmware update on July 20, 2026 to remediate the issue.
Key Takeaways
- Use of a hard-coded Bluetooth authentication key allows unauthorized vehicle control commands.
- Attackers within Bluetooth range can unlock doors or immobilize the engine.
- A firmware update was released on July 20, 2026 to address the vulnerability.