Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across 🇺🇸🇨🇳🇯🇵🇰🇷🇹🇼🇩🇪🇫🇷🇨🇭🇦🇹🇳🇱🇧🇪🇵🇱🇨🇦🇱🇺🇪🇺. Stay ahead.

1962advisories found
Clear filters
Results
cvelistv5medium

cve-2026-74588

This advisory addresses a vulnerability in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation, specifically a flaw where the chunk's transport pointer may not stay synchronized with the queue it is placed on. An attacker could potentially exploit this inconsistency to cause a denial-of-service condition or other undefined behavior in systems using SCTP. The severity is not explicitly stated in the advisory, but the issue affects the Linux kernel, which could be relevant where SCTP is deployed in automotive systems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74586

This advisory addresses a vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation, specifically a flaw where a new transport is not properly cleared when a peer is removed. An attacker could potentially exploit this memory management issue to cause a denial of service or other undefined behavior in systems using SCTP. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel with SCTP is deployed in automotive systems, such as in-vehicle infotainment or telematics units. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74585

The advisory describes a fix in the Linux kernel for the Thunderbolt driver, where the DROM dual link port number is now bounded before indexing into the software ports array, preventing a potential out-of-bounds access. An attacker could exploit this flaw to cause memory corruption or a system crash, though the advisory does not specify a severity rating. This could be relevant where the Thunderbolt driver is deployed in automotive systems, such as for high-speed data transfer in infotainment or diagnostic equipment, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74584

cvelistv5medium

cve-2026-74581

This advisory addresses a Linux kernel networking issue where IPv6 routing table results can be improperly suppressed, potentially allowing an attacker to exploit incorrect routing behavior. The technical impact involves disruption or manipulation of network traffic handling, with severity not explicitly stated in the provided text. This could be relevant where Linux-based systems with IPv6 networking are deployed in automotive contexts, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74582

The advisory addresses a Linux kernel issue where the packet socket implementation fails to use a consistent hard_header_len in non-ring send paths, which could allow an attacker to exploit inconsistent header length handling. The technical impact is not explicitly detailed in the provided text, and no severity rating is stated. This could be relevant where the Linux kernel is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium

cve-2026-74580

This advisory addresses a vulnerability in the Linux kernel's vhost subsystem, specifically the failure to reset the vring metadata cache when a vring is reconfigured. An attacker could potentially exploit this flaw to cause incorrect data handling or system instability. The severity is not explicitly stated in the advisory. This could be relevant where the Linux kernel's vhost subsystem is deployed in automotive systems, such as for virtualized in-vehicle infotainment or telematics. Confirm applicability through the product SBOM or dependency inventory.

nvdlow · 3.7

cve-2026-78124

strongSwan versions 5.0.2 through 6.0.7 contain a memory-release flaw in the openssl plugin related to PKCS#7 certificate enumeration, which could allow an attacker to cause a memory leak. This could be relevant where strongSwan is deployed in automotive systems, such as in vehicle-to-cloud or telematics connections. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.7

cve-2026-55785

free5GC, an open-source 5G core network implementation, has a vulnerability in its AUSF component prior to version 1.4.5. The issue involves non-constant-time authentication comparisons and logging of sensitive authentication values (XRES*), which could expose authentication material to anyone with access to system logs. The severity is not explicitly rated, but the fix is available in version 1.4.5. This could be relevant where free5GC is deployed in automotive systems, such as for vehicle-to-network communications, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.7

cve-2026-13735

Zephyr's WireGuard implementation had a flaw where certain keepalive packets were accepted without verifying their cryptographic authentication tag, allowing an attacker to send a spoofed message that could trigger a false VPN-connected status signal. The impact is limited to integrity of this status signal, with no data decryption, key disclosure, or service disruption. This could be relevant where Zephyr's WireGuard is deployed in automotive systems, and the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.7

cve-2026-11809

This vulnerability affects the UpdateHub OTA client, which is the over-the-air update mechanism used in Zephyr RTOS-based automotive systems for firmware updates to ECUs, telematics units, and other vehicle controllers. A malicious or compromised update server can send a specially crafted probe response that triggers an out-of-bounds read of uninitialized heap memory, potentially crashing the update thread and causing a denial of service that could interrupt critical vehicle software updates. The issue is network-triggerable and rated as a denial-of-service risk, though it does not allow data theft or code execution, and the fix involves properly initializing the memory buffer.

cvelistv5low · 3.7

cve-2026-11811

This vulnerability affects the real-time operating system Zephyr, which is deployed in vehicle ECUs, ADAS controllers, and body control modules, specifically impacting its UpdateHub over-the-air update client. An attacker on the network can disrupt the OTA connection to cause a socket descriptor leak with each failed attempt, gradually exhausting the device's networking resources until a denial-of-service condition occurs that requires a reboot to recover. The severity is low because the leak rate is limited by the default 24-hour OTA poll interval, and only builds with the UpdateHub client enabled are affected.

csaf_suselow · 3.7

suse-su-2026:3490-1

This Wi-Fi vulnerability impacts the wireless connectivity used in vehicle OTA updates, in-car hotspots, and dealership diagnostic tools. The flaw allows an attacker positioned between the vehicle and a RADIUS authentication server to inject malicious packets, forcing Wi-Fi authentication to fail, which could disrupt critical wireless services. Additionally, the update fixes two other issues that could crash the Wi-Fi software, potentially causing a denial of service for in-vehicle connectivity, though the overall severity is moderate.

cvelistv5low · 3.6

cve-2026-11742

This vulnerability affects the Zephyr RTOS, a real-time operating system deployed in vehicle ECUs, ADAS controllers, and body control modules, where its queue functions are used for data buffers in Bluetooth, USB, and networking subsystems. An attacker with local access could exploit a race condition to free memory while it is being read, potentially leaking stale heap contents or causing a system crash or memory corruption. The severity is low because exploitation requires winning a small timing window with local access, and the fix is a simple lock addition to make the peek operations safe.

csaf_nozominetworkslow · 3.5

nn-2026:18-01

A cross-site request forgery vulnerability exists in the login functionality of Guardian/CMC versions before 26.3.0, affecting both standard and SAML logins due to missing anti-CSRF token validation. An attacker could exploit this to perform unauthorized actions on behalf of an authenticated user, such as submitting forged login requests. The risk level for Nozomi customers is rated as Medium. This could be relevant where Guardian/CMC is deployed in automotive or industrial systems, as Nozomi products are used for network visibility and security monitoring. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.5

cve-2026-76816

Netty, a widely used network application framework, has a vulnerability in its MQTT encoder that fails to validate certain fields like client IDs and topic names, allowing attackers to insert null bytes into MQTT messages. This could lead to routing, access-control, or identity mismatches in downstream brokers, and the issue is fixed in versions 4.1.137.Final and 4.2.17.Final. This could be relevant where Netty is deployed in automotive systems, such as for vehicle-to-cloud communication, and the severity is not explicitly stated in the advisory. Confirm applicability through the product SBOM or dependency inventory.

nvdlow · 3.5

cve-2026-18278

The advisory describes a vulnerability in the Sony XAV-9500ES, an automotive head unit, where a network-adjacent attacker who can pair a malicious Bluetooth device could exploit an out-of-bounds read in the handling of Bluetooth L2CAP packets to disclose sensitive information. This flaw could be combined with other vulnerabilities to execute arbitrary code on the device. The severity is not explicitly rated in the advisory, but the technical impact includes information disclosure and potential code execution. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.3

cve-2026-54548

kas is a setup tool for bitbake-based projects, and prior to version 5.4, it disables SSH host key checking persistently for the local user, which could allow an attacker to intercept SSH sessions and compromise their confidentiality or integrity. This could be relevant where kas is deployed in automotive systems, such as in build or continuous integration environments for automotive software. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.1

cve-2026-14367

The advisory describes a race condition in the I3C IBI subsystem of the Zephyr operating system, where statically-allocated work nodes are managed through an unsynchronized free-list. An attacker with physical access to an I3C peripheral bus could trigger high-frequency interrupts to exploit this race, potentially causing a crash, hang, or memory corruption, with denial of service being the most realistic impact. This could be relevant where Zephyr is deployed in automotive systems using I3C chip-to-chip communication, though the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.1

cve-2026-13480

The advisory describes an out-of-bounds read vulnerability in the LoRaWAN FUOTA fragmented data block transport handler within the Zephyr RTOS. An attacker holding the device's session keys could craft a malicious downlink to cause the handler to read past the end of a buffer, potentially copying adjacent memory into decoder buffers and the FUOTA flash image, though the impact is limited to a bounded read with no direct data disclosure or system compromise. This could be relevant where Zephyr's LoRaWAN stack is deployed in automotive systems, such as in telematics or fleet management devices, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.1

cve-2026-13479

The advisory describes an out-of-bounds read vulnerability in the LoRaWAN clock-synchronization service of the Zephyr operating system, where a crafted AppTimeAns downlink message can cause the handler to read up to 5 bytes past the end of the decrypted payload. An attacker who is a malicious or compromised network/application server, or holds session keys, could exploit this to apply a garbage time correction to the device's clock offset, though there is no data disclosure, crash, or severe impact—only a minor integrity effect on the device's time estimate. This could be relevant where Zephyr's LoRaWAN stack is deployed in automotive systems, such as in telematics or fleet applications, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.1

cve-2026-76926

Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 contain a reachable assertion in the BUSMASTER file parser that causes an abnormal exit, allowing a denial of service. This could be relevant where Wireshark is deployed in automotive systems, such as for analyzing CAN bus traffic, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.1

cve-2026-76891

Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 contain a vulnerability involving an expired pointer dereference in the sharkd component, which can cause a crash and lead to a denial of service. An attacker could exploit this to disrupt analysis operations. This could be relevant where Wireshark is deployed in automotive systems for network diagnostics or telematics analysis, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.1

cve-2026-76890

Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 contain a vulnerability involving an expired pointer dereference that can cause a crash in the sharkd component, leading to a denial of service. An attacker could exploit this to disrupt analysis functionality. This could be relevant where Wireshark is deployed in automotive systems for network diagnostics or telematics analysis, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5low · 3.1

cve-2026-76885

Wireshark versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 contain a buffer over-read vulnerability in the Tektronix K12xx file parser, which can cause a crash and lead to a denial of service when processing a malicious file. This could be relevant where Wireshark is deployed in automotive systems for network analysis or diagnostics, as an attacker could exploit this to disrupt analysis tools. Confirm applicability through the product SBOM or dependency inventory.