Automotive researchers catalogued 345 new vulnerabilities in the second quarter of 2026, with high-severity flaws more than doubling to 161, according to PCA Cyber Security’s quarterly threat intelligence report published July 29.
The Budapest-based firm said 94% of the quarter’s vulnerabilities carry low attack complexity, meaning they can be exploited without specialized tools or lengthy preparation. Fourteen entry methods were observed, but Local Shell access dominated, accounting for 28% of all findings. That technique uses diagnostic and debug interfaces to reach a vehicle’s onboard computers and extract data or compromise critical systems.
PCA also flagged a shift toward broader targets. White-hat research showed rentable EV chargers and shared e-bikes and e-scooters could be disabled remotely through hacked cloud-based authentication, opening the door to city-wide infrastructure outages. Separate research demonstrated how unencrypted data from a second-hand car head unit could reveal the previous owner’s driving history and personal details.
Supply chains are the new pressure point. An emerging extortion group claimed a Canadian regional automotive parts retailer on its leak site, while Qilin said it breached a large Japanese components manufacturer through subsidiaries in Europe and North Africa. The World Leaks group published more than 630 GB from an Indian electronics contract manufacturer, including engineering documents belonging to one of the world’s largest EV makers.
A ransomware incident at a UK-based automotive data and vehicle valuation provider caused what PCA called a regional valuation blackout, leaving dealers, insurers and OEMs without access to critical data.
The report argues that tracking CVEs is no longer enough. With attackers going after fleets, charging networks, cloud backends and suppliers, the industry needs to harden the ecosystem rather than individual vehicles.