SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.
GlobalCybersecurity

High-severity automotive vulnerabilities more than doubled in the second quarter

PCA Cyber Security's Q2 threat report counted 345 unique automotive vulnerabilities, 161 of them high-severity — up from 75 the quarter before.

Automotive vulnerability disclosures accelerated sharply in the second quarter, according to PCA Cyber Security’s quarterly threat intelligence report: 345 unique vulnerabilities were recorded, with 161 classed as high-severity — more than double the 75 high-severity findings of the first quarter.

The profile of the findings matters as much as the count. Ninety-four percent of the vulnerabilities had low attack complexity, and local shell access was the most common entry method at 28 percent. In-vehicle systems accounted for nearly 40 percent of observed attacks, but the researchers report targeting shifting toward fleets, supply chains and cloud backends — the aggregation points where one compromise scales across many vehicles.

The report’s central recommendation is software composition analysis: as software-defined vehicles pull in more third-party and open-source components, knowing what is actually running in the fleet becomes the precondition for defending it — the same visibility that UNECE R155 monitoring obligations already assume manufacturers have.

Why it mattersThe vulnerability curve is climbing exactly where SDV architectures concentrate value — fleets, cloud backends and supply chains, not individual cars.

Source: PCA Cyber Security, Q2 2026 threat intelligence report

The SDV Sector Brief

The month in vehicle software — top stories, what our readers read most, and an editor's take. First Tuesday of the month, 08:30 CET. Double opt-in, unsubscribe anytime.