SHEET 04VULNERABILITY MGMT · ISO 21434 CL.8 · UN R155 · EU CRA

A CVE drops at 03:00.
You already know which vehicles are exposed.

Continuous vulnerability monitoring for automotive fleets. Every SBOM component is matched against live CVE feeds, scored for exploitability, and traced through your risk model to the exact projects and vehicles affected — with VEX triage attached so nobody chases noise.

Trace a live CVE CycloneDX · SPDX · NVD · CNVD · VEX
CVE-watch — live
FEED SYNC nvd · cnvd · osv → 1,204 delta
MATCH CVE-2026-31842 libmqtt-embedded 2.4.1
└ CVSS 9.1 · EPSS 0.71 · CISA-KEV
└ 3 components · 5 projects · 1,180 units
VEX affected · fix 2.4.3 · escalated
ESCALATE INC-4471 → risk recompute · supplier pinged
STATION 1 · INTAKE

SBOM & component
intake.

CycloneDX and SPDX bills-of-materials land in object storage first, then parse into the graph as real components with versions and package URLs. Hash-dedup means an unchanged SBOM never re-runs the pipeline.

INPUT ← CycloneDX · SPDX
STORE → S3-first · parsed to graph
DEDUP → unchanged SBOM skipped
NVD · CNVD · OSV · GitHub ← FEEDS
EPSS · CISA-KEV · ENISA-KEV ← SIGNALS
caught tonight, not next audit ← CONTINUAL
STATION 2 · MATCH

Continuous CVE
matching.

Every component is matched against live databases — NVD, OSV, GitHub, MITRE and CNVD — enriched with EPSS, CISA-KEV and ENISA-KEV signals. Monitoring is continual, so a CVE published today is caught tonight.

SUPPLIER & VULNERABILITY MONITORING · FLEET 6 FINDINGS · SORT: EXPLOIT FORECAST
CRIT 9.1
CVE-2026-31842 libmqtt-embedded 2.4.1 · Telematics ECU
Bosch-T1 VEX: affected
HIGH 8.2
CVE-2026-04477 freertos-kernel 10.5.1 · Powertrain MCU
NXP Under investigation
HIGH 7.5
CVE-2026-10457 openssl 3.0.11 · Gateway ECU
Continental VEX: fixed 3.0.13
MED 6.1
CVE-2026-22019 curl 8.4.0 · Infotainment
Denso VEX: affected
LOW 3.7
CVE-2025-77201 lwip 2.1.3 · ADAS sensor
Valeo VEX: not affected

CVE identifiers shown are illustrative.

STATION 3 · TRIAGE

VEX and risk,
not a firehose.

Each finding is scored for exploit likelihood and forecast — stable, likely-to-escalate, escalated — then linked into the risk model, so a CVE becomes a path through the real architecture. VEX status is emitted so consumers get a decision.

SCORE → exploit forecast · EPSS
LINK → risk-path through architecture
EMIT → VEX · CSAF out
exploitable → managed incident ← ESCALATE
incident → risk recompute ← POST-PROD
supplier receives their CVEs ← UPSTREAM
STATION 4 · ESCALATE

Escalate, notify,
recompute.

An exploitable finding escalates to a managed incident that triggers a risk recompute, so post-production posture stays current. The supplier workspace lets Tier-1s share evidence upstream and receive the CVEs that touch their parts — see Operations.

TITLEVULNERABILITY MANAGEMENT & CONTINUOUS MONITORING
STANDARDISO 21434 CL.8 · UN R155
FORMATSCDX · SPDX · CSAF-VEX
FEEDSNVD · CNVD · OSV