Automotive Vulnerabilities. Hunted worldwide every 24 hours, across 🇺🇸🇨🇳🇯🇵🇰🇷🇹🇼🇩🇪🇫🇷🇨🇭🇦🇹🇳🇱🇧🇪🇵🇱🇨🇦🇱🇺🇪🇺. Stay ahead.
1962advisories found
fkie_nvdhigh · 8.8
cve-2026-11826
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the OpenPLC_v3 runtime used for programmable logic control. An authenticated attacker with web interface access can send a crafted request that overflows a buffer in the Modbus master component, corrupting adjacent memory and causing the PLC process control loop to crash, resulting in denial of service. The issue is severe because it can halt production line operations, and no fix is available as the vendor has archived the repository and confirmed it does not affect the newer OpenPLC Runtime v4.
csaf_mettlertoledogmbhhigh · 8.8
vde-2026-066
This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically METTLER TOLEDO FreshWay B/D scales running Windows. An attacker could exploit unpatched Windows vulnerabilities to remotely execute code, elevate privileges, or disclose sensitive information, increasing operational risk. The severity is high, and immediate installation of cumulative Windows security patches through March 2026 is required to protect manufacturing systems.
nvdhigh · 8.7
cve-2026-54571
ESPAsyncWebServer, a web server library used on ESP32, ESP8266, RP2040 and RP2350 microcontrollers, has an integer overflow in its multipart form-data parser before version 3.11.1. A remote attacker could send a request with a 256-byte multipart boundary, causing the parser to loop endlessly, consume excessive CPU, and trigger a watchdog reset that reboots the device, resulting in a denial of service. This could be relevant where ESPAsyncWebServer is deployed in automotive or embedded systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 8.7
cve-2026-52836
OpenDDS, an open source implementation of the Data Distribution Service (DDS) messaging standard, has a flaw before version 3.34.0 in which a network attacker can crash a reachable participant by sending a malformed RTPS UDP submessage, causing an invalid memory read and process termination. No authentication or victim interaction is required, and the impact is a remotely exploitable denial of service that destroys the DDS entities hosted by the affected participant. This could be relevant where OpenDDS is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 8.7
cve-2026-73174
Advantech EKI-1242EIMS devices running firmware V1.06.01 have a vulnerability in the edgserver management protocol where sensitive information is transmitted in cleartext. A network-adjacent attacker who passively observes traffic could intercept management communications and recover sensitive device identity and network metadata. This could be relevant where the affected Advantech device is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 8.7
cve-2026-33197
AMI AptioV BIOS contains a vulnerability where a privileged user with local access can bypass secure boot due to an incomplete list of disallowed inputs, potentially leading to arbitrary code execution and impacting system confidentiality, integrity, and availability. This could be relevant where AMI AptioV is deployed in automotive systems, such as in vehicle infotainment or control units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 8.7
cve-2026-14297
The advisory describes a buffer overflow vulnerability in the Bluetooth Continuous Glucose Monitoring Service's Record Access Control Point write handler, where an authenticated Bluetooth Low Energy peer can overflow a fixed 20-byte buffer into adjacent memory. The technical impact is unpredictable because it depends on the specific firmware's memory layout, which varies by build. This could be relevant where the nRF Connect SDK is deployed in automotive systems, such as for Bluetooth-based vehicle access or telematics, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 8.7
cve-2026-84304
gRPC-Go, a Go language implementation of gRPC, has a vulnerability prior to version 1.83.1 where fragmented HTTP/2 data frames can cause excessive heap memory usage, potentially leading to a denial of service via out-of-memory termination. An unauthenticated remote attacker could exploit this by sending millions of one-byte frames across concurrent streams. This could be relevant where gRPC-Go is deployed in automotive systems, such as in vehicle-to-cloud communication or telematics services. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 8.7
cve-2026-81721
The advisory describes a denial-of-service vulnerability in openssl_encrypt versions before 1.4.9, where attackers can craft malicious encrypted files with invalid key derivation function (KDF) cost parameters, causing unbounded memory allocation and potentially crashing the system without authentication. This could be relevant where openssl_encrypt is deployed in automotive systems, such as for secure data storage or communication, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 8.7
cve-2026-81703
openssl_encrypt versions before 1.4.9 fail to validate whether embedded post-quantum private keys are actually encrypted, allowing attackers to craft files with unencrypted keys that decrypt under any password and bypass authentication, producing attacker-chosen plaintext with false integrity verification. This could be relevant where openssl_encrypt is deployed in automotive systems, such as for secure file storage or key management. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 8.7
cve-2026-81699
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs. This could be relevant where openssl_encrypt is deployed in automotive systems, such as in file-processing or encryption components; confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 8.7
cve-2026-81687
openssl_encrypt versions before 1.4.9 fail to limit the time spent on key derivation function iterations specified in file metadata, allowing attackers to craft files with extremely high iteration counts that consume CPU resources for an unbounded period, causing a denial of service. This could be relevant where openssl_encrypt is deployed in automotive systems, such as in file-handling or encryption components. Confirm applicability through the product SBOM or dependency inventory.
csaf_cisahigh · 8.7
icsa-26-239-02
The advisory describes vulnerabilities in the All-Line Equipment Company Fuel-Boss product, which could allow attackers to remotely execute arbitrary commands or code on affected systems. The affected component is the University of Washington IMAP Toolkit, which has a command injection flaw and a stack-based buffer overflow, and the advisory also notes a separate issue in PHP versions up to 7.1.5 that could enable remote code execution under certain configurations. This could be relevant where Fuel-Boss is deployed in automotive or transportation systems, as the advisory lists Transportation Systems as a critical infrastructure sector, but the automotive connection is not confirmed. Confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 8.7
cve-2026-62243
Netty versions 4.2.0 through 4.2.16 and versions through 4.1.136 disable TLS hostname verification on the OpenSSL client path under specific conditions, allowing a man-in-the-middle attacker to present a certificate for a different hostname that is accepted without validation. The issue is fixed in versions 4.2.17 and 4.1.137. This could be relevant where Netty is deployed in automotive systems, such as in telematics or communication modules, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 8.7
cve-2026-73523
COVESA Open1722 through 0.9.2 has a vulnerability in its CAN listener component where an unauthenticated remote attacker can send a specially crafted UDP datagram to cause the system to leak about 18 KB of process stack memory onto the CAN bus as roughly 240 CAN frames. The issue stems from an integer truncation error that makes the listener transmit far more data than intended. This could be relevant where Open1722 is deployed in automotive systems for Ethernet-to-CAN bridging; confirm applicability through the product SBOM or dependency inventory.
cvelistv5high · 8.7
cve-2026-8798
This vulnerability affects the cryptographic libraries used in automotive secure boot, over-the-air update verification, and secure communication between ECUs, where Bouncy Castle FIPS is often embedded in vehicle software stacks. An attacker exploiting a hardware or hypervisor-level failure of the CPU’s entropy source could cause the vehicle’s security functions to hang indefinitely, leading to a denial of service that might block critical operations like authentication or data decryption. The issue is severe because it can freeze the entire application using the library, but it is now fixed in version 2.1.3, so affected systems must be updated to prevent potential lockups.
NVDhigh · 8.7
CVE-2026-13505
CVE-2026-13505 affects Bouncy Castle for Java FIPS (BC-FJA) versions prior to 1.0.2.7, 2.0.2, and 2.1.3, where sensitive key material is zeroized via finalization, which can be delayed under load, causing memory exhaustion and leaving keys in heap longer than intended. This is particularly relevant for automotive systems using BC-FJA for cryptographic operations, as it could lead to denial of service or increased risk of key exposure. The fix uses a Cleaner to ensure timely disposal on Java 9 and later.
cvelistv5high · 8.7
cve-2026-66360
This vulnerability affects the IEC 61850 communication protocol stack used in electric vehicle charging stations, substation automation, and smart grid infrastructure that connects to automotive manufacturing plants and EV charging networks. An attacker can send a specially crafted network connection to trigger a memory read error, causing the system to crash and stop responding, which could disrupt EV charging operations or industrial control systems in automotive factories. The issue is rated as high severity because it requires no authentication and can be exploited remotely over the network to cause a denial of service.
cvelistv5high · 8.7
cve-2026-63559
This vulnerability affects the open62541 OPC UA stack, which is used in industrial control systems deployed in automotive manufacturing plants and assembly lines for secure machine-to-machine communication. An integer overflow in the UA_Variant arrayDimensions product computation could allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information from the plant network. This is a high-severity issue that could expose proprietary manufacturing data or control system details if exploited.
fkie_nvdhigh · 8.7
cve-2026-50032
This vulnerability affects the industrial control systems deployed in automotive manufacturing plants and assembly lines, where the MMS protocol is used for robot and equipment communication. A network-adjacent attacker could crash the server by sending a specially crafted WriteRequest with an empty listOfData field, causing a denial of service that halts production line operations. This is a high-severity issue that could disrupt vehicle assembly without requiring authentication.
fkie_nvdhigh · 8.7
cve-2026-6924
This vulnerability affects the SiWx917 wireless chipset used in automotive IoT modules for telematics, keyless entry, and vehicle-to-everything communication. A bug in the entropy initialization causes the random number generator to produce predictable seeds, which could allow an attacker to guess cryptographic keys or session tokens used in Matter-based vehicle systems. The severity is limited because the impacted repository is already deprecated, but any vehicles still using this chipset for secure communications could be at risk.
fkie_nvdhigh · 8.7
cve-2026-50039
This vulnerability affects the CAN bus / automotive Ethernet network that connects ECUs within vehicles, specifically a stack-based buffer overflow in a component that processes Read Requests. An attacker could exploit this to cause memory corruption, potentially leading to system crashes or arbitrary code execution on the vehicle network. The severity is high, as it could compromise critical vehicle functions if exploited remotely or through physical access.
nvdhigh · 8.6
cve-2026-73177
Nozomi Networks Labs found that the Advantech EKI-1242EIMS running firmware V1.06.01 accepts firmware images through its authenticated web management interface without verifying cryptographic signatures or certificates. An attacker with administrator-level access could install modified firmware, leading to full persistent compromise of the device. This could be relevant where the Advantech EKI-1242EIMS is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 8.6
cve-2026-73176
Advantech EKI-1242IEIMS firmware V1.06.01 contains an OS command injection flaw in its web management interface, which a remote authenticated attacker could exploit to run arbitrary commands as root. This could be relevant where this device is deployed in automotive systems, such as industrial or roadside network environments. Confirm applicability through the product SBOM or dependency inventory.
nvdhigh · 8.6
cve-2026-73171
Advantech EKI-1242EIMS devices running firmware V1.06.01 contain a flaw in the backup-restore workflow that lets a remote authenticated attacker overwrite arbitrary files on the device by uploading a crafted backup archive through the web management interface. This could be relevant where such Advantech industrial networking equipment is deployed in automotive manufacturing or road-transport systems. Confirm applicability through the product SBOM or dependency inventory.