Rethinking automotive cyber risk for the age of accelerated vulnerability discovery
Automotive vulnerabilities jumped to 345 in Q2 2026, with shared cloud and supplier flaws widening fleet exposure.
PCA Cyber Security threat-intelligence lead Tamás Pentz argues that connected vehicles shift risk from physical tampering to shared cloud, mobile, OTA, diagnostic, and supplier systems. The firm's Q2 2026 automotive intelligence recorded 345 new vulnerabilities, up 30 percent from Q1, while high-severity findings rose from 75 to 161 and only five were low severity. Cited research includes remotely disabling a Shanghai public charger through weak device identity, a Honda Civic head-unit update weakness, highly privileged access on a BYD Dolphin head unit, and three of eight CAN diagnostic attacks succeeding against a 2021 Hyundai Elantra. The piece also cites supplier exposure, including a Qilin listing tied to a Japanese Tier-1's European and North African subsidiaries, and cautions that unverified breach claims need corroboration.