Automotive Cybersecurity News Q2 2026

Read time:00:04

Release date:7.30.2026

Every quarter, PCA Cyber Security's Threat Intelligence team analyses how the automotive threat landscape is evolving in our Global Automotive Threat Intelligence Reports.

Q1 2026 showed that automotive cybersecurity risk was accelerating. Q2 reveals something different: attackers and researchers alike are becoming more selective, focusing on vulnerabilities that can cause the greatest operational disruption.

During Q2, we identified 345 unique automotive-specific vulnerabilities, a 30% increase over Q1. Even more concerning, 161 of those vulnerabilities were classified as High severity—more than double the number identified in the previous quarter.

The message is becoming increasingly clear. Automotive cybersecurity is no longer just about protecting individual vehicles. The greatest risks now extend across fleets, cloud platforms, supply chains, and connected mobility infrastructure.

As our CTO, Vlad Ryabyshkin explains:

"The increased automation of cybersecurity vulnerability discovery and exploitation is well documented. The outcome of that trend is more interesting, and Q2 vulnerabilities give clear clues as to how those outcomes are playing out for the automotive industry. Hackers and ethical researchers are prioritising vulnerabilities with higher risk profiles and maximum blast radius potential. Rampant targeting of OEMs via supply chains risks fuelling the automotive threat landscape further. Manual defences are no longer sufficient - the industry needs active resilience with focus on Software Composition Analysis (SCA) if it's to secure the era of software-defined vehicles."

Our full Q2 2026 Global Automotive Threat Intelligence Report about resources/threat intelligence quarterly report is available free of charge and provides detailed analysis of the vulnerabilities, underground activity, emerging attack techniques, and regulatory developments shaping today's automotive cybersecurity landscape.

Here are some of the key findings.

More Vulnerabilities, Greater Impact

The increase in vulnerability volume is significant, but the shift in severity is even more notable.

Of the 345 automotive vulnerabilities identified during Q2, 161 were High severity, compared to 75 in Q1. At the same time, 94% required only Low Attack Complexity, meaning they can often be exploited without specialised tooling or extensive preparation.

Rather than simply discovering more vulnerabilities, attackers are increasingly finding weaknesses capable of compromising critical vehicle functions, exposing sensitive customer information, or disrupting connected mobility services.

Automotive Attackers Are Expanding Their Blast Radius

The way vulnerabilities are being exploited is evolving as well.

While Local Shell remained the single most common entry point during Q2, accounting for 28% of observed vulnerabilities, the bigger trend is that both offensive security researchers and cybercriminals are increasingly targeting systems capable of affecting many vehicles simultaneously rather than compromising individual vehicles one by one.

This shift is visible across the research community and real-world attacks alike, reflecting a growing focus on cloud services, shared infrastructure, backend systems, and software supply chains.

The Risk Extends Beyond the Vehicle

Several notable incidents tracked during Q2 illustrate how automotive cyber risk increasingly affects the wider mobility ecosystem.

Among the most significant developments were:

  • Security research demonstrating how cloud-based authentication weaknesses could allow rentable EV chargers, shared e-bikes, and e-scooters to be remotely disrupted.

  • A ransomware attack against a UK automotive data and vehicle valuation provider that disrupted dealers, insurers, and OEMs by cutting access to critical operational data.

  • Research showing that second-hand vehicle infotainment systems can still contain unencrypted personal information, exposing previous owners long after a vehicle has changed hands.

  • Continued ransomware activity targeting automotive suppliers, including intellectual property theft and large-scale data leaks affecting manufacturers across multiple regions.

Together, these examples demonstrate that today's automotive attack surface extends well beyond the vehicle itself.

Supply Chains Are Becoming a Primary Target

Our monitoring of cybercriminal forums, ransomware leak sites, and underground marketplaces also identified an important shift in attacker behaviour.

Rather than directly targeting OEM networks, threat actors are increasingly compromising suppliers, distributors, and manufacturing partners to gain access to valuable intellectual property and operational data.

For many organisations, this makes software supply chains and third-party ecosystems one of the largest sources of cyber risk.

Automotive Security Must Move Beyond CVEs

As software-defined vehicles continue to grow in complexity, simply tracking published vulnerabilities is no longer enough.

Understanding whether vulnerable components actually exist within deployed software—and whether patches have truly been applied—has become essential.

That's why we believe the industry must move beyond traditional CVE monitoring toward continuous Software Bill of Materials (SBOM) validation and Software Composition Analysis (SCA), enabling manufacturers to verify software integrity throughout the vehicle lifecycle rather than relying on periodic assessments.

For the complete breakdown of Q2 findings, including vulnerability statistics, underground threat activity, supply-chain attacks, ethical hacking research, and regulatory developments, download the full Q2 2026 Global Automotive Threat Intelligence Report about resources/threat intelligence quarterly report.

Article tags

automotive cybersecurity

vehicle security

global automotive threat intelligence report

Popular tags

automotive cybersecurity

pci pts

payment device security

automotive threat intelligence

pci dss

pcautomotive

pcacybersecurity

payment security

cra

pts device security