
Automotive Zero-Day Vulnerabilities
VIEW DATABASEThe Criticality of Zero-Day Vulnerabilities Beyond Known Threats
Zero-day vulnerabilities currently have no vendor patch solution, but their exploitability has already been confirmed. What does this mean to organizations and enterprises?
Potential for Serious Damage
Confirmed zero-day vulnerabilities empower malicious actors to exploit them to execute attacks that could have dire consequences.
Lack of Defense
In the absence of a solution, attackers have ample time to exploit zero-day vulnerabilities repeatedly.
Wide-Ranging Impact
Given that the same open-source software and modules are utilized across multiple ECUs, zero-day vulnerabilities can affect numerous components.
Real-World Exploits Triggered by Zero-Day Vulnerabilities
at Pwn2Own Vancouver
Real-World Exploit Intelligence
The Latest Automotive Zero-Day Vulnerability Database
The following is a list of automotive vulnerabilities discovered by researchers through Trend Zero Day Initiative™ (ZDI) that are yet to be publicly disclosed. This initial list comprises zero-day vulnerabilities discovered at Pwn2Own Automotive, hosted by VicOne with Trend ZDI. For each vulnerability, the affected vendor has been contacted and is expected to develop a patch. These vulnerabilities are handled according to the Trend ZDI Disclosure Policy. The zero-day identifier of a vulnerability refers to the candidate (CAN) number assigned to the vulnerability by Trend ZDI.
| Zero-day identifier | CVE | Category | Impact |
|---|
Want to know if you've been impacted?
Contact us to assess risks →
Gain Advantage With Unique Zero-Day Insights
VicOne's best-in-class automotive threat intelligence includes early access to vital information on automotive zero-day vulnerabilities:
- Gain Early Warning: We empower OEMs, suppliers, and stakeholders with risk assessment capabilities. We will assess whether your components or software versions are impacted by zero-day vulnerabilities ahead of competitors, allowing for better resource allocation during planning. This approach complies with the spirit of ISO/SAE 21434 by helping you monitor newly emerged vulnerabilities.
- Gain Early Protection: We will evaluate how to collaborate with you based on attack tactics, techniques, and procedures to create effective virtual patches for safeguarding your system.
Want to know if you've been impacted?
Contact us to assess risks →

No. 1
in vulnerability discovery and disclosure since 2007*
5+ years
of partnership with Tesla for Pwn2Own, starting in 2017
*Source: Omdia Research, Quantifying the Public Vulnerability Market: 2024 Edition
More Insights Into Automotive Zero-Day Vulnerabilities From VicOne
GAIN INSIGHTS INTO AUTOMOTIVE CYBERSECURITY
How Mythos Is Reshaping Vulnerability Management: What CISOs Need to Know About VulnOps
Learn how Mythos-ready security and always-on VulnOps help CISOs respond faster to AI-accelerated vulnerabilities, exploit chains, and cyber risk at scale.
READ MORE →From Perception to Action: What GB/T 45502-2025 Signals for Service Robot Security
China's GB/T 45502-2025 establishes information security requirements for service robots and their supporting systems. Learn what it means for cybersecurity across the robot lifecycle.
READ MORE →What Lies Beyond Mythos: What Automakers and Suppliers Need to Prepare for Now
AI-chained attack vectors are changing vulnerability triage. Learn why automakers and suppliers must move from CVSS scores to attack-path prioritization before July 2026.
READ MORE →VicOne Situational Awareness Report: 477 Cybersecurity Incidents, 160 Ransomware Cases, and Other Automotive Threat Highlights in Q2 2026
VicOne's Situational Awareness Report in Q2 2026 breaks down cybersecurity threats across the automotive, transportation, and logistics sectors by region, domain, ransomware activity, vulnerability type, and AI-related risk.
READ MORE →