Pwn2Own Automotive 2026: Hackers Exploit 29 Zero-Day Vulnerabilities
Executive Summary
On the second day of Pwn2Own Automotive 2026, hackers exploited 29 new zero-day vulnerabilities. This brings the event's cumulative total to 66 unique zero-days and $955,750 in prize money. The vulnerabilities are currently unpatched and actively exploited within the contest environment.
Vulnerability Details
- Affected Product: Automotive systems, including connected vehicles and electric vehicle chargers
- Identifier: N/A
- CVSS Score: N/A
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Immediate action is required due to the active exploitation of these vulnerabilities.
- Attack Vector: The attack vectors vary but include exploiting vulnerabilities in infotainment systems and EV chargers.
- Ease of Exploit: The ease of exploitation varies depending on the vulnerability, but the success of the Pwn2Own competition demonstrates that skilled researchers can successfully exploit these flaws.
Action Plan
- Immediate Action: Apply patches as soon as vendors release them. Upgrade to the latest software versions to mitigate known vulnerabilities.
- Workaround: Implement network segmentation and intrusion detection systems to monitor and potentially block malicious activity.
- Detection: Monitor systems for unusual activity and review security logs for potential indicators of compromise (IOCs).
Relevant professional terms
- Zero-Day Vulnerability
- A software flaw that is unknown to the vendor and for which no patch is available, making it susceptible to immediate exploitation.
- Exploit
- A technique or piece of code that takes advantage of a vulnerability in a system to cause unintended behavior, such as gaining unauthorized access or executing malicious code.
Source: Bleeping Computer
