CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Acrisure KARR BT and DR-100

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3836

As cited

Copy frozen at (site build).

vulnerabilities

Acrisure KARR BT and DR-100

Acrisure KARR BT and DR-100 automotive anti-theft systems contain a hard-coded Bluetooth authentication key shared across affected devices, allowing attackers within Bluetooth range to issue unauthorized commands including door unlocking and engine immobilization. Acrisure released a firmware update on July 20, 2026 to address CVE-2026-18411, which carries a CVSS 3.1 score of 8.1.

Why it matters: Fleet operators and vehicle owners using Acrisure KARR BT or DR-100 systems must immediately apply the July 20, 2026 firmware update to prevent remote vehicle control attacks from nearby threat actors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Acrisure KARR BT and DR-100

CVE-2026-18411 affects Acrisure KARR BT and DR-100 vehicle anti-theft systems through a hard-coded shared Bluetooth authentication key that allows nearby attackers to issue unauthorized commands. An attacker within Bluetooth range could unlock doors or disable the engine without authentication. Acrisure released a firmware update on July 20, 2026, to remediate the vulnerability.

Why it matters: Fleet operators and vehicle owners using Acrisure KARR BT or DR-100 systems must apply the July 20, 2026 firmware update immediately to prevent unauthorized vehicle control by attackers with Bluetooth access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Acrisure KARR BT and DR-100

CVE-2026-18411 affects Acrisure KARR BT and DR-100 vehicle anti-theft systems through a hard-coded shared Bluetooth authentication key that allows nearby attackers to issue unauthorized commands. An attacker within Bluetooth range could unlock doors or disable the engine without authentication. Acrisure released a firmware update on July 20, 2026, to remediate the vulnerability.

Why it matters: Fleet operators and vehicle owners using Acrisure KARR BT or DR-100 systems must apply the July 20, 2026 firmware update immediately to prevent unauthorized vehicle control by attackers with Bluetooth access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary