
Automotive Zero-Day Vulnerabilities
VIEW DATABASEThe Criticality of Zero-Day Vulnerabilities Beyond Known Threats
Zero-day vulnerabilities currently have no vendor patch solution, but their exploitability has already been confirmed. What does this mean to organizations and enterprises?
Potential for Serious Damage
Confirmed zero-day vulnerabilities empower malicious actors to exploit them to execute attacks that could have dire consequences.
Lack of Defense
In the absence of a solution, attackers have ample time to exploit zero-day vulnerabilities repeatedly.
Wide-Ranging Impact
Given that the same open-source software and modules are utilized across multiple ECUs, zero-day vulnerabilities can affect numerous components.
Real-World Exploits Triggered by Zero-Day Vulnerabilities
at Pwn2Own Vancouver
Real-World Exploit Intelligence
The Latest Automotive Zero-Day Vulnerability Database
The following is a list of automotive vulnerabilities discovered by researchers through Trend Zero Day Initiative™ (ZDI) that are yet to be publicly disclosed. This initial list comprises zero-day vulnerabilities discovered at Pwn2Own Automotive, hosted by VicOne with Trend ZDI. For each vulnerability, the affected vendor has been contacted and is expected to develop a patch. These vulnerabilities are handled according to the Trend ZDI Disclosure Policy. The zero-day identifier of a vulnerability refers to the candidate (CAN) number assigned to the vulnerability by Trend ZDI.
| Zero-day identifier | CVE | Category | Impact |
|---|
Want to know if you've been impacted?
Contact us to assess risks →
Gain Advantage With Unique Zero-Day Insights
VicOne's best-in-class automotive threat intelligence includes early access to vital information on automotive zero-day vulnerabilities:
- Gain Early Warning: We empower OEMs, suppliers, and stakeholders with risk assessment capabilities. We will assess whether your components or software versions are impacted by zero-day vulnerabilities ahead of competitors, allowing for better resource allocation during planning. This approach complies with the spirit of ISO/SAE 21434 by helping you monitor newly emerged vulnerabilities.
- Gain Early Protection: We will evaluate how to collaborate with you based on attack tactics, techniques, and procedures to create effective virtual patches for safeguarding your system.
Want to know if you've been impacted?
Contact us to assess risks →

No. 1
in vulnerability discovery and disclosure since 2007*
5+ years
of partnership with Tesla for Pwn2Own, starting in 2017
*Source: Omdia Research, Quantifying the Public Vulnerability Market: 2024 Edition
More Insights Into Automotive Zero-Day Vulnerabilities From VicOne
GAIN INSIGHTS INTO AUTOMOTIVE CYBERSECURITY
How BADBOX-Linked Malware Turned Automotive Head Units into Proxy Nodes
VicOne shows how BADBOX-linked malware used DoFun Android head units, weak MQTT security, and trusted OTA updates to push silent, persistent installs.
READ MORE →From Pwn2Own Automotive 2026: Seven Kenwood DNR1007XR Vulnerabilities Now Patched
Kenwood patched seven DNR1007XR vulnerabilities discovered at Pwn2Own Automotive 2026, addressing direct and multistep paths to root access.
READ MORE →FCC, CRA, and IEC 62443: Three Gates to Robotics Market Readiness
Robot manufacturers face distinct FCC, the EU Cyber Resilience Act (CRA), and IEC 62443 requirements. Learn how shared security workflows can support readiness across all three.
READ MORE →How Mythos Is Reshaping Vulnerability Management: What CISOs Need to Know About VulnOps
Learn how Mythos-ready security and always-on VulnOps help CISOs respond faster to AI-accelerated vulnerabilities, exploit chains, and cyber risk at scale.
READ MORE →