SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.
GlobalCybersecurity

Automotive vulnerability disclosures more than doubled in the second quarter

PCA Cyber Security's Q2 threat report counted 345 unique automotive vulnerabilities, 161 of them high-severity — up from 75 the quarter before.

Automotive vulnerability disclosures accelerated sharply in the second quarter, according to PCA Cyber Security’s quarterly threat intelligence report: 345 unique vulnerabilities were recorded, with 161 classed as high-severity — more than double the 75 high-severity findings of the first quarter.

The profile of the findings matters as much as the count. Ninety-four percent of the vulnerabilities had low attack complexity, and local shell access was the most common entry method at 28 percent. In-vehicle systems accounted for nearly 40 percent of observed attacks, but the researchers report targeting shifting toward fleets, supply chains and cloud backends — the aggregation points where one compromise scales across many vehicles.

The report’s central recommendation is software composition analysis: as software-defined vehicles pull in more third-party and open-source components, knowing what is actually running in the fleet becomes the precondition for defending it — the same visibility that UNECE R155 monitoring obligations already assume manufacturers have.

Why it mattersThe vulnerability curve is climbing exactly where SDV architectures concentrate value — fleets, cloud backends and supply chains, not individual cars.

Source: PCA Cyber Security, Q2 2026 threat intelligence report

The SDV Sector Brief

The week in vehicle software — top stories, one-line briefs, and what's coming. Every Sunday, 17:00 CET. Double opt-in, unsubscribe anytime.