Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across 🇺🇸🇨🇳🇯🇵🇰🇷🇹🇼🇩🇪🇫🇷🇨🇭🇦🇹🇳🇱🇧🇪🇵🇱🇨🇦🇱🇺🇪🇺. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5high · 8.3

cve-2026-82549

A vulnerability was identified in Linux Foundation Magma 1.9.0, specifically in the SecurityModeComplete Handler, which fails to properly validate an integrity check value. An attacker could exploit this remotely, and the exploit is publicly available, potentially compromising the integrity of the communication session. This could be relevant where Magma is deployed in automotive systems, such as in fleet or telematics networks, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.3

cve-2026-77236

FreeRTOS-Kernel versions before 11.3.1 lack a minimum size check in the SecureContext_AllocateContext function, which could allow a local user to trigger an out-of-bounds write and corrupt secure-world heap metadata by supplying an undersized stack size. This could be relevant where FreeRTOS-Kernel is deployed in automotive systems, such as in embedded control units, and the advisory recommends upgrading to version 11.3.1 or later to remediate the issue. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.3

cve-2026-77235

FreeRTOS-Kernel versions before 11.3.1 contain a missing privilege check in the secure context cleanup handler, which could allow a local user to trigger a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. The advisory does not confirm automotive deployment, but this could be relevant where FreeRTOS-Kernel is deployed in automotive systems, as it is a real-time operating system kernel often used in embedded environments. Confirm applicability through the product SBOM or dependency inventory. The remediation is to upgrade to version 11.3.1 or later.

fkie_nvdhigh · 8.3

cve-2026-16317

This vulnerability affects the TLS 1.3 encryption library s2n-tls, which is used in automotive cloud services for secure OTA updates and telematics data transmission. An active man-in-the-middle attacker can silently drop individual encrypted data records without detection, potentially causing request/response desynchronization or undetectable data loss in connected vehicle systems. This is a high-severity issue affecting all TLS 1.3 connections, and upgrading to s2n-tls v1.7.6 is recommended.

csaf_siemenshigh · 8.2

ssa-330084

Siemens has identified a Client Code Execution vulnerability in its Desigo CC product family, where an attacker can craft a malicious graphics document containing embedded scripts. If a user with sufficient privileges opens this document, the script executes on the client application, allowing the attacker to write arbitrary files to the client's operating system, potentially compromising the system and enabling lateral movement within the organization. The advisory does not specify a severity rating, and while Desigo CC is a building automation product, the advisory does not explicitly state an automotive connection, so this could be relevant where Desigo CC is deployed in automotive or related facilities; confirm applicability through the product SBOM or dependency inventory.

csaf_opensusehigh · 8.2

rhsa-2026:59723

This security update addresses multiple vulnerabilities in the Linux kernel, including issues in memory management, network tunneling, netfilter, SCTP, and zram components. An attacker could potentially cause denial of service through excessive CPU usage, system crashes from use-after-free conditions, or incorrect network packet filtering behavior. The advisory does not confirm automotive deployment, but this could be relevant where the Linux kernel is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.2

cve-2026-77237

A vulnerability in FreeRTOS-Kernel versions before 11.3.1 could allow an unprivileged task on MPU-enabled ports with queue sets enabled to read privileged kernel memory. This could be relevant where FreeRTOS-Kernel is deployed in automotive systems, such as in embedded control units, and an attacker could exploit this to access sensitive data. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.2

cve-2026-63362

This vulnerability affects the OPC UA communication protocol used in automotive manufacturing plants and assembly lines for secure machine-to-machine data exchange. An attacker could send a specially crafted UDP packet to trigger an integer underflow in the signature verification process, potentially causing a denial of service that disrupts production systems. The severity is moderate, as it requires network access to the OPC UA server but could halt critical automation processes in vehicle manufacturing.

cvelistv5high · 8.1

cve-2026-76886

The advisory describes a heap-based buffer overflow in the C12.22 protocol dissector of Wireshark, affecting versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18, which can cause a crash and lead to a denial of service. An attacker could exploit this by crafting malicious network traffic to crash the application. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.1

cve-2026-12633

This advisory describes a vulnerability in the Zephyr operating system's IPv6 networking code, specifically in how it handles 6LoWPAN Context Options within Router Advertisements. An unauthenticated attacker on the same network link could send a specially crafted packet that triggers an out-of-bounds memory write, potentially causing a denial of service through system crashes or memory corruption. The severity is high due to the remote exploitability from adjacent networks, and while Zephyr is an embedded operating system often used in automotive applications, this advisory does not confirm specific automotive deployment. This could be relevant where Zephyr is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5high · 8.1

cve-2026-63035

This vulnerability affects the OPC UA industrial control protocol stack used in automotive manufacturing plants and assembly lines for secure machine-to-machine communication. An authenticated attacker could exploit a heap use-after-free flaw in the TransferSubscriptions service to cause a denial of service or potentially execute arbitrary code on affected systems. This is a critical risk that could disrupt production line operations or allow unauthorized control of manufacturing equipment.

fkie_nvdhigh · 8.1

cve-2026-13308

This vulnerability affects EV charging infrastructure including wallboxes, DC fast chargers, and charging station management systems, specifically the Autel MaxiCharger AC Elite Home EV charger. An attacker can remotely execute arbitrary code on the device without needing any authentication by sending a specially crafted WebSocket message that triggers an integer underflow error. This is a critical severity issue because it allows complete takeover of the charger, potentially disrupting charging operations or using the device as a foothold for broader network attacks.

csaf_cisahigh · 8.1

icsa-26-204-06

This vulnerability affects the IEC 61850 protocol stack used in substation automation systems for electric vehicle charging infrastructure, smart grid integration, and manufacturing plant power management. An unauthenticated network-adjacent attacker could crash critical services or execute arbitrary code by sending specially crafted messages, potentially disrupting protection and control functions in energy and transportation systems. The vulnerabilities are rated as critical, with remote code execution demonstrated when ASLR is disabled, though no active exploitation has been reported yet.

nvdhigh · 8.0

cve-2026-56967

A heap buffer overflow in the Cellular Modem component could allow an attacker within close range to execute code remotely without any user interaction or extra privileges. This could be relevant where the affected modem component is deployed in automotive systems, since cellular modems are sometimes used for vehicle connectivity. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.0

cve-2026-42807

Bosch Sensortec COINES_SDK versions 2.10 through 2.12.2 contain a heap-based buffer overflow in its PC bridge protocol decoder, which trusts a packet length from an external device and can overwrite host memory. A malicious or compromised USB or Bluetooth Low Energy peripheral could crash the host process or potentially execute arbitrary code. This could be relevant where COINES_SDK is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.0

cve-2026-18282

The advisory describes a heap-based buffer overflow vulnerability in the Sony XAV-9500ES, an automotive head unit, specifically in its handling of AVRCP Bluetooth packets. An attacker who can pair a malicious Bluetooth device with the unit could exploit this flaw to execute arbitrary code on the device. The severity is high, as it allows remote code execution in the context of the device, though the attacker must first gain Bluetooth pairing access. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 8.0

cve-2026-18281

The advisory describes a heap-based buffer overflow vulnerability in the Sony XAV-9500ES, a device that is directly automotive-related as an in-car infotainment system. An attacker who can pair a malicious Bluetooth device with the system could exploit this flaw in the handling of Bluetooth L2CAP packets to execute arbitrary code on the device. The stated technical impact is remote code execution in the context of the device, with the vulnerability requiring network-adjacent access and prior Bluetooth pairing. Confirm applicability through the product SBOM or dependency inventory.

csaf_microsofthigh · 7.9

cve-2026-78408

The advisory describes a vulnerability in util-linux, specifically in the nsenter tool's --join-cgroup option, which leaks root cgroup migration authority. An attacker could exploit this flaw to gain unauthorized control over cgroup settings, potentially leading to privilege escalation or system compromise. The severity is not explicitly stated in the provided text. This could be relevant where util-linux is deployed in automotive systems, such as in embedded Linux environments, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

nvdhigh · 7.8

cve-2026-57014

A missing bounds check in the NFC HAL component phNxpNciHal_ext.cc could allow a local attacker to trigger an out-of-bounds write, leading to local escalation of privilege without needing user interaction or extra execution privileges. This could be relevant where Android NFC HAL components are deployed in automotive systems, such as in in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

csaf_siemenshigh · 7.8

ssa-328642

Multiple Siemens industrial products are affected by a vulnerability known as "Copy Fail," which stems from a flaw in the Linux kernel's cryptographic interface (algif_aead) that was previously operating in-place. An attacker could potentially exploit this issue to cause a failure in data copying during cryptographic operations, leading to a denial-of-service condition. Siemens has released software updates for some products and recommends applying them, while also advising network protection measures for devices where fixes are not yet available. This advisory does not explicitly mention automotive systems, so this could be relevant where these Siemens industrial products are deployed in automotive manufacturing or related environments; confirm applicability through the product SBOM or dependency inventory.

csaf_microsofthigh · 7.8

cve-2026-78410

The advisory describes a vulnerability in util-linux where restricted bind mounts do not pin the source, allowing an attacker to redirect x-mount.owner, group, or mode settings. This could enable unauthorized changes to file ownership or permissions on the mounted filesystem. The severity is not explicitly stated in the provided text. This could be relevant where util-linux is deployed in automotive systems, such as in embedded Linux environments for infotainment or control units. Confirm applicability through the product SBOM or dependency inventory.

csaf_siemenshigh · 7.8

ssa-069220

This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically Siemens Simcenter Nastran software used for engineering simulation and structural analysis in vehicle design. An attacker could exploit a stack overflow by tricking a user into running the software with a malicious file argument, potentially achieving remote code execution on the affected workstation. Siemens has released an updated version (V2606) to fix this issue, and organizations should prioritize updating their engineering workstations to mitigate the risk.

csaf_siemenshigh · 7.8

ssa-621657

This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically Siemens Solid Edge software used for 3D design and engineering of vehicle components. An attacker could exploit file parsing flaws in PAR, PSM, or DFT files to crash the application or execute malicious code on an engineer’s workstation, potentially disrupting vehicle design workflows or compromising sensitive manufacturing data. The severity is high, with multiple critical memory corruption vulnerabilities, and Siemens recommends updating to Solid Edge SE2026 Update 7 immediately to mitigate the risk.

csaf_siemenshigh · 7.8

ssa-584312

This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically the Simcenter Femap software used for engineering analysis and simulation in vehicle design. An attacker could exploit file parsing flaws by tricking an engineer into opening a malicious BMP file, potentially causing the application to crash or allowing arbitrary code execution on the workstation. The severity is high because successful exploitation could compromise engineering workstations and potentially disrupt vehicle development processes, so Siemens recommends updating to the latest version immediately.

csaf_siemenshigh · 7.8

ssa-138516

This vulnerability affects industrial control systems deployed in automotive manufacturing plants and assembly lines, specifically Siemens Parasolid software used for CAD/CAM design and machining of vehicle components. An attacker could exploit the out-of-bounds read flaw by tricking an engineer into opening a malicious X_T file, potentially crashing the design workstation or executing arbitrary code on it. Siemens has released patched versions, and updating is strongly recommended to prevent disruption to vehicle design and production operations.