Automotive vulnerability disclosures more than doubled in the second quarter
PCA Cyber Security's Q2 threat report counted 345 unique automotive vulnerabilities, 161 of them high-severity — up from 75 the quarter before.
Automotive vulnerability disclosures accelerated sharply in the second quarter, according to PCA Cyber Security’s quarterly threat intelligence report: 345 unique vulnerabilities were recorded, with 161 classed as high-severity — more than double the 75 high-severity findings of the first quarter.
The profile of the findings matters as much as the count. Ninety-four percent of the vulnerabilities had low attack complexity, and local shell access was the most common entry method at 28 percent. In-vehicle systems accounted for nearly 40 percent of observed attacks, but the researchers report targeting shifting toward fleets, supply chains and cloud backends — the aggregation points where one compromise scales across many vehicles.
The report’s central recommendation is software composition analysis: as software-defined vehicles pull in more third-party and open-source components, knowing what is actually running in the fleet becomes the precondition for defending it — the same visibility that UNECE R155 monitoring obligations already assume manufacturers have.
Source: PCA Cyber Security, Q2 2026 threat intelligence report