Georgia Tech researchers reproduced seven flaws on commercial hardware and report that the new in vehicle network still carries the message layer weaknesses that older versions of the Controller Area Network have carried for years.
Georgia Tech researchers say they have confirmed seven security vulnerabilities in CAN XL, the next-generation networking standard automakers are preparing to use as the main wiring between the dozens of small computers that run future cars. The flaws were reproduced on commercial hardware during a formal analysis presented at USENIX Security 2026.
The team, led by Zhaozhou Tang with collaborators from Purdue and the Korea Advanced Institute of Science and Technology, also reports that the new standard retains the basic message-sending and error-handling rules, known as the MAC sub-layer, that left older versions of the Controller Area Network (CAN) exposed to network compromise. In a release, co-author Saman Zonouz called it a "narrow window" to fix the standard before it ships in production vehicles.
CAN XL is not yet widely deployed, so a specification-level flaw can still be patched before millions of cars are already on the road. Vehicles stay in service for a decade or more, which is why a standard-level weakness baked in now is hard to walk back.
The researchers validated the seven flaws on commercial CAN XL controllers and ran two multi-stage attacks on a testbed simulating real vehicle traffic. Georgia Tech's release notes the attacks assume a prior compromise of a computer already on the in-vehicle network; the research does not show how an attacker would first reach that network. Proposed mitigations include formally verified revisions to the standard.
The USENIX paper is in the 2026 symposium proceedings; the institutional release was published on September 24.