The second day of Pwn2Own Automotive 2026 has accelerated the competition dramatically, with security researchers uncovering dozens of critical vulnerabilities in automotive systems and EV charging infrastructure.
The event has now awarded over $516,500 across 37 unique zero-day vulnerabilities, establishing a landmark year for automotive security disclosures.
Vulnerability Landscape: Charging Systems Under Siege
EV charging stations emerged as the primary attack surface on Day Two, with multiple successful exploits targeting Grizzl-E Smart 40A, Alpitronic HYC50, and ChargePoint Home Flex systems.
The Charging Connector Protocol/Signal Manipulation add-on proved particularly attractive, generating numerous successful attacks that exposed authentication bypasses, command injection flaws, and buffer overflow vulnerabilities.
Fuzzware.io dominated early rounds, securing $50,000 for exploiting three critical bugs in the Phoenix Contact CHARX SEC-3150.
The team’s multi-vulnerability chain, combining authentication bypass with privilege escalation,n demonstrated the compounding risks when multiple flaws exist in a single system.
Later, the same team earned another $30,000 for command injection vulnerabilities in ChargePoint infrastructure.
In-vehicle infotainment systems remained a secondary but significant attack vector.
Team MAMMOTH successfully exploited command injection vulnerabilities in Alpine iLX-F511 systems for $10,000, while Neodyme AG targeted Sony XAV-9500ES with a buffer overflow (CWE-120), netting $10,000.
The Kenwood DNR1007XR received sustained pressure from multiple teams, with both n-day and zero-day command injection exploits yielding between $2,500 and $5,000 per successful demonstration.

A notable breakthrough came when Technical Debt Collectors exploited Automotive Grade Linux (AGL), chaining three distinct vulnerabilitiesan out-of-bounds read, memory exhaustion, and heap overflow for $40,000 and 4 Master of Pwn points.
This attack represents a critical concern for the automotive industry’s push toward open-source platforms in connected vehicles.
The high frequency of vulnerability collisions where multiple teams discovered identical flaws underscores the accessibility of certain attack vectors.
Alpine iLX-F511 systems experienced at least four collision incidents, with researchers earning reduced bounties of $2,500 per collision rather than the full vulnerability price.
This pattern suggests predictable weaknesses that multiple security researchers identified through similar methodologies.

Day Two standings reveal Fuzzware.io as the leading team with multiple six-figure performances, while independent researchers and smaller teams like Summoning Team demonstrated competitive viability through targeted exploits.
The $50,000 payout for multi-bug chains incentivizes researchers to develop sophisticated exploit techniques rather than simple single-vulnerability demonstrations.
As Pwn2Own Automotive 2026 progresses, automotive manufacturers face mounting pressure to address not just isolated vulnerabilities but the systemic weaknesses enabling multi-stage attacks.
The prevalence of authentication bypasses, command injection flaws, and memory safety issues indicates fundamental design and implementation deficiencies across multiple vendors.
These findings will likely reshape automotive security standards and drive industry-wide patch management initiatives in the coming quarters.
The competition continues to expose critical gaps in automotive cybersecurity posture that real-world threat actors are undoubtedly monitoring with keen interest.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.