Exposure monitor
Vulnerabilities
Automotive Vulnerabilities. Hunted worldwide every 24 hours, across πΊπΈπ¨π³π―π΅π°π·πΉπΌπ©πͺπ«π·π¨ππ¦πΉπ³π±π§πͺπ΅π±π¨π¦π±πΊπͺπΊ. Stay ahead.
1962advisories found
csaf_cisacritical Β· 9.1
icsa-26-237-07
The advisory covers the FURUNO FA-50 Class B AIS Transponder, a marine navigation device used in transportation systems. An attacker with network access and credentials could alter device settings, and some configuration changes may be possible without authentication. The stated impact is that successful exploitation could allow an attacker to alter device settings, with no known public exploitation reported. This could be relevant where the transponder is deployed in automotive or road-transport systems, though the advisory focuses on maritime use. Confirm applicability through the product SBOM or dependency inventory.
csaf_siemenscritical Β· 9.1
ssa-825228
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically Siemens Siveillance Video Management Servers used for facility surveillance. An attacker with edit permissions to the Management Server could execute arbitrary code on the server, potentially disrupting plant security monitoring or gaining deeper access to factory networks. Siemens has released updated versions to fix this issue, and immediate patching is strongly recommended to protect manufacturing operations.
csaf_siemenscritical Β· 9.1
ssa-814963
This vulnerability affects the Mendix low-code platform, which is used by some automotive manufacturers and suppliers to build vehicle-related applications such as fleet management portals, dealer service tools, and production tracking dashboards. A documentation gap in Mendix's access rules could lead developers to unintentionally expose sensitive user data or allow privilege escalation, potentially giving an anonymous user access to all stored records. Siemens rates this as a high-severity issue and urges developers to review their access rule configurations immediately.
csaf_siemenscritical Β· 9.0
ssa-254516
Siemens has disclosed a vulnerability in the Open Interface Services (OIS) web module used in its Siveillance Control and Siveillance Control Pro products. An attacker could exploit this flaw to upload arbitrary files, potentially gaining root-level access and fully compromising the affected system. Siemens has released patches and recommends updating to the latest versions to mitigate the risk.
certfr_aviscritical
certfr-2026-avi-1179
Multiple vulnerabilities were found in HPE Aruba Networking EdgeConnect SD-WAN Gateways and Orchestrator products, and some of them let an attacker run arbitrary code remotely, gain elevated privileges, or cause a remote denial of service. The advisory also lists impacts including data integrity and confidentiality compromise, server-side request forgery, and security policy bypass. This could be relevant where these SD-WAN components are deployed in automotive systems, for example in connected vehicle, plant, or fleet network infrastructure; confirm applicability through the product SBOM or dependency inventory.
certfr_aviscritical
certfr-2026-avi-1166
Multiple vulnerabilities have been discovered in Fortinet products, including FortiSIEM, FortiManager, FortiOS, FortiProxy, FortiSandbox, FortiSOAR, FortiAnalyzer, FortiPAM, FortiClient and FortiMonitorOnSight, at various versions listed in the advisory. An attacker could exploit some of these to achieve remote arbitrary code execution, privilege escalation, or remote denial of service, with impacts also including data confidentiality and integrity compromise and security policy bypass. This could be relevant where Fortinet products are deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
csaf_cisahigh Β· 8.8
icsa-26-260-02
Mitsubishi Electric GX Works3 and Motion Control Settings contain an authentication flaw that lets a local attacker bypass block password checks and gain access to control programs. Once in, the attacker could view, tamper with, destroy, or delete those programs. The advisory does not state a numeric severity score, but it is classified as critical manufacturing infrastructure software, and this could be relevant where such engineering tools are deployed in automotive manufacturing or control environments; confirm applicability through the product SBOM or dependency inventory.
nvdhigh Β· 8.8
cve-2026-73173
Nozomi Networks Labs found a missing-authentication flaw in the edgserver management protocol of Advantech EKI-1242EIMS firmware V1.06.01, which lets a remote unauthenticated attacker invoke critical device-management functions such as network reconfiguration, reboot, reset, and firmware upgrade via crafted requests to TCP port 5058. The advisory does not confirm an automotive deployment, so this could be relevant where the affected Advantech device is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh Β· 8.8
cve-2026-56882
A logic error in the Cellular Modem component could allow an attacker to disclose information and potentially achieve remote code execution without any user interaction or extra privileges. This could be relevant where the Cellular Modem component is deployed in automotive systems, since cellular modems are commonly used for vehicle connectivity. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh Β· 8.8
cve-2026-0200
A heap buffer overflow in the Cellular Modem component could allow a remote attacker to write out of bounds and escalate privileges without any user interaction or additional execution privileges. This could be relevant where the Cellular Modem component is deployed in automotive systems, since cellular modems are commonly used for vehicle connectivity. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh Β· 8.8
cve-2026-0159
A missing bounds check in the Cellular Modem component could allow an attacker to write outside intended memory boundaries, potentially leading to remote code execution without requiring any user interaction or extra privileges. This could be relevant where cellular modem components are deployed in automotive systems, since such modems are commonly used for vehicle connectivity. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high Β· 8.8
cve-2026-57163
PJSIP, a multimedia communication library, has a stack buffer overflow vulnerability in its GnuTLS TLS backend when parsing a peer certificate's Subject Alternative Name. A network attacker presenting a crafted certificate could trigger this during a TLS handshake, potentially causing application termination or memory corruption. This could be relevant where PJSIP is deployed in automotive systems, such as for telematics or communication functions, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high Β· 8.8
cve-2026-83596
A flaw was found in WebKitGTK where processing malicious web content can cause memory corruption due to improper memory handling. This could be relevant where WebKitGTK is deployed in automotive systems, such as in infotainment or embedded web browsers. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh Β· 8.8
cve-2026-55637
genieacs-mcp, an MCP server for GenieACS, has a vulnerability prior to version 0.3.2 where its HTTP listener on localhost lacks authentication and does not validate Host or Origin headers. A malicious website could exploit DNS rebinding to access this listener and invoke operations against the GenieACS NBI, potentially exposing or modifying CPE management state such as device reboots, firmware tasks, and TR-069 parameter changes. This could be relevant where genieacs-mcp is deployed in automotive systems that use GenieACS for device management; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high Β· 8.8
cve-2026-13212
The advisory describes a vulnerability in the Zephyr virtio driver where a malicious or compromised virtio backend can supply an out-of-range descriptor id, leading to an arbitrary function-pointer call in the guest's interrupt context. This can result in code execution or a crash, with no guest privileges or user interaction required, and the severity is high due to the control-flow-hijack primitive. This could be relevant where Zephyr's virtio driver is deployed in automotive systems, such as in virtualized or partitioned environments, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high Β· 8.8
cve-2026-78376
A use-after-free vulnerability exists in WebKitGTK, where processing malicious web content can cause improper memory handling and lead to memory corruption. An attacker could exploit this by delivering crafted web content to trigger the flaw, potentially compromising the affected system. The advisory lists Red Hat Enterprise Linux 6 through 9 as affected, with no severity rating stated. This could be relevant where WebKitGTK is deployed in automotive systems, such as in infotainment or embedded web browsers. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high Β· 8.8
cve-2026-12522
The advisory describes a stack buffer overflow in Zephyr's HL7800 cellular modem driver, where a malicious or impersonated cellular network can send a crafted response with an overlong address field during normal network attach. This can cause a crash or potentially allow control-flow hijacking on the device, with no user interaction required. The affected component is a modem driver, which could be relevant where Zephyr is deployed in automotive systems with cellular connectivity; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high Β· 8.8
cve-2026-9771
The advisory describes a vulnerability in the Zephyr operating system's flash_copy() system call, where missing validation of device pointers allows an unprivileged user to execute arbitrary code in supervisor mode, leading to local privilege escalation, denial-of-service, or information disclosure. The affected component is the flash driver subsystem, which could be relevant where Zephyr is deployed in automotive systems, such as in embedded controllers or telematics units. Confirm applicability through the product SBOM or dependency inventory.
csaf_pilzgmbhcokghigh Β· 8.8
ppsa-2026-003
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the Pilz IndustrialPI industrial PC running Linux. An attacker with local access who can execute code on the device could exploit multiple Linux kernel flaws to gain full control over the system, potentially disrupting production operations or manipulating safety-critical processes. The severity is high for manufacturing environments, and Pilz recommends updating to firmware version 15.06.2026 or patching the kernel to version 6.12.91-revpi0-rpi-v8 to mitigate the risk.
csaf_cisahigh Β· 8.8
icsa-26-211-08
This vulnerability affects the OPC UA communication protocol stack (open62541) used in automotive manufacturing plants and assembly lines for industrial control system interoperability. An attacker could exploit these flaws to cause denial of service, disclose sensitive information, or potentially execute arbitrary code on affected systems, with the most severe issues involving heap memory corruption and out-of-bounds writes. CISA recommends isolating these systems from the internet and using VPNs for remote access, though no active exploitation has been reported yet.
cvelistv5high Β· 8.8
cve-2026-65423
This vulnerability affects the OPC UA industrial communication protocol used in automotive manufacturing plants and assembly lines for robot control and production monitoring. An integer overflow in the open62541 library could allow a remote attacker to trigger an out-of-bounds write, potentially causing system crashes or enabling code execution on factory floor equipment. This is a critical severity issue that could disrupt vehicle production or allow unauthorized control of manufacturing systems.
fkie_nvdhigh Β· 8.8
cve-2026-51274
This vulnerability affects the ESP32 chipset, which is used in automotive-grade chips for telematics, infotainment, and aftermarket audio systems in vehicles. An attacker can exploit a heap-based buffer overflow in the MP3 audio parser by sending a crafted file, potentially causing a system crash, leaking sensitive information, or executing malicious code. This is a critical security issue that could compromise vehicle audio systems and connected services.
csaf_adstecindustrialitgmbhhigh Β· 8.8
vde-2026-076
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the ADS-TEC IRF1000 and IRF3000 devices used for industrial networking. An attacker with low-level access could escalate to administrator privileges, lock out user accounts, crash the configuration service, or trick users into phishing sites, while bundled components like dnsmasq and OpenSSL introduce risks of DNS cache poisoning and denial-of-service attacks. The severity is high for the privilege escalation and account lockout flaws, though the OpenSSL issues are low severity, and all vulnerabilities are fixed in firmware version 2.3.0.
csaf_weidmuellerinterfacegmbhcokghigh Β· 8.8
vde-2026-081
This vulnerability affects industrial security routers used in automotive manufacturing plants and assembly lines to segment and protect network traffic between production equipment and enterprise systems. Multiple flaws in the router firmware could allow an attacker to gain full administrator access, lock out legitimate users, crash the device, or redirect personnel to phishing sites, while additional bugs in bundled software could enable DNS poisoning or denial-of-service attacks. Weidmueller has released firmware version V2.3.0 to fix all these issues, and you should update affected routers immediately and change default passwords.
fkie_nvdhigh Β· 8.8
cve-2026-51275
This vulnerability affects the ESP32 chipset, which is used in automotive-grade infotainment systems, telematics units, and aftermarket audio modules for media playback and hands-free calling. An attacker can exploit a heap-based buffer overflow by sending a specially crafted MP3 file to the device, potentially allowing remote code execution or a system crash. This is a critical security issue that could compromise vehicle audio systems and requires immediate patching.