By Tamás Pentz, Head of Threat Intelligence, PCA Cyber Security
Automotive cybersecurity has traditionally focused on putting controls into vehicles that counter the ways criminals could physically tamper with a vehicle.
However, the growing adoption of connected vehicles calls for a reassessment of assumptions. Today a weakness in one connected system can compromise many vehicles.
Modern vehicles rely on cloud platforms, mobile applications, over-the-air (OTA) update services, diagnostic systems and software from multiple third-party suppliers. EV charging introduces yet another connected layer.
As these dependencies increase, the chances of an exposed component leaving a vehicle vulnerable to cyber attack grow higher.
Analysis of global automotive threat intelligence recorded 345 new automotive vulnerabilities discovered in the second quarter of 2026, up 30 per cent from Q1.
High-severity findings accounted for much of that increase, rising from 75 in Q1 to 161 in Q2. Only five vulnerabilities were classified as low severity.
The Q2 findings saw a rise in both vulnerability volume and severity, but the numbers alone do not speak to the growing blast radius of automotive vulnerabilities.
That growth is one of the most startling patterns emerging in automotive security and needs to be acted on rather than passively left to run its course.
A bigger attack surface
14 distinct entry methods were observed across Q2’s unique automotive vulnerabilities, although most were concentrated around a relatively small number of them.
This matters because a vulnerability’s potential reach depends partly on where it sits within the wider architecture.
A weakness in an isolated electronic control unit (ECU), for example, may affect one vehicle, while a flaw in a common backend, authentication mechanism or software component could affect an entire fleet of vehicles across multiple manufacturers.
Recent analysis of EV charging infrastructure offers a useful example. Researchers demonstrated weaknesses in device identifiers and cloud authentication that allowed a public charger to be disabled via the service’s own application.
In a live demonstration from a conference hall, a charger in Shanghai was switched from “available” to “disabled” within seconds.
The researchers assessed that, in a worst-case scenario, this weakness could scale to disable charging infrastructure city-wide.
The physical charger was not the primary problem; the weakness was in the systems responsible for identifying and authenticating connected devices. Shared software creates a similar concentration risk.
If a vulnerable component or trust mechanism is implemented across multiple vehicle programs or services, fixing one affected asset does not address the underlying exposure.
The same question applies inside the vehicle: what can an attacker reach after gaining access to one system?
Deeper access
Local Shell accounted for more than 28 per cent of Q2 vulnerabilities, making it the most common attack vector. Local Shell describes a method of gaining command-line access to an onboard system, often through diagnostic or debug interfaces.
Q2 research illustrates the significance of gaining access to an onboard system. Analysis of a Honda Civic’s head unit revealed that a weakness in its firmware update process allowed for the installation of a malicious image with brief physical access.
Similarly, reverse engineering a BYD Dolphin head unit discovered vulnerabilities such as CAN read and write access, an unlocked bootloader and highly privileged services, along with flaws in its update mechanisms.
These findings show how seemingly peripheral systems act as a foothold from which to access other parts of the vehicle architecture. Where infotainment or telematics systems connect to other vehicle networks or trusted services, a compromise can broaden the scope of an attack.
Not all vulnerabilities are made equal
The kinds of white hat automotive security research cited so far offer early warnings about weaknesses in automotive systems. But how a vulnerability is reached is always important context.
The strongest evidence comes from structured, repeatable testing. An example from Q2 saw researchers test the CAN transport protocol against a 2021 Hyundai Elantra using two diagnostic tools; three of eight attack scenarios succeeded, including stalling diagnostic sessions, concealing stored fault codes, and returning altered sensor readings.
It showed that the channel a technician relies on to report a vehicle’s true state can itself be subverted, which is a more general problem than any single ECU defect.
Other findings are opportunistic rather than systematic. A teardown of a single salvaged telematics unit detailed in research published in April revealed unencrypted GNSS logs, hardcoded Wi-Fi credentials, a passwordless guest account and other exposed services.
That’s enough to reconstruct the vehicle’s history and serves as a reminder that sensitive data can outlive a vehicle itself, surviving resale or scrapping.
It’s a real vulnerability, but one that potentially impacts just one unit, not necessarily a whole fleet of vehicles.
The weakest tier is underground breach claims. Credibility varies widely, and unverified claims need independent supporting evidence before they can be treated as confirmed.
Supply chain exposure
It would be remiss to not acknowledge how supply chain dependencies are increasingly introducing security risks beyond the direct control of OEM’s.
This year we’ve has seen major cases involving suppliers and overseas subsidiaries, including a Qilin listing centered on a major Japanese Tier-1’s European and North African subsidiaries.
We’ve also seen significant intellectual property exposure, including engineering data from an EV manufacturer leaked through a compromised contract manufacturer, and a ransomware incident affecting a UK vehicle valuation provider create a regional data blackout for dealers, insurers and OEMs.
All this points to the need for stronger oversight of external dependencies. OEMs have to assume design data shared with partners will eventually leak.
But there’s still a case for extending endpoint detection and response and segmentation standards to subsidiaries to limit the risk of such leaks and compromise via the supply chain.
Containing the blast radius
The rise of software-defined vehicles has expanded the potential reach of automotive vulnerabilities.
With vulnerability volumes and share of these being high-severity on the rise, it’s never been more crucial for automakers and OEMs to establish comprehensive, complete visibility into all the dependencies and components that could leave vehicles and components open to newly discovered vulnerabilities.
Without that clear picture, the response to vulnerabilities as they emerge is slower. That’s not good enough to counter the acceleration of vulnerability discovery.

