CYBER DELTA FORCESearch

EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act

Manufacturers selling connected products in the European Union face a new legal duty starting Sept.

CDF News DeskThe Cyber Express10 Sept 2026, 4:39 pm
Image courtesy of The Cyber Express. Original report
CDF REPORT

Manufacturers selling connected products in the European Union face a new legal duty starting Sept. Report actively exploited vulnerabilities to authorities within 24 hours of confirming them. The obligation arrives 15 months ahead of the Cyber Resilience Act's full application date of Dec. The CRA covers products with digital elements placed on the EU market, a category broad enough to take in enterprise software, consumer IoT devices, industrial controllers and much of the component software beneath them.

And the harmonised standards that will define what adequate compliance looks like are still working through public enquiry, so companies are building processes against a moving target.

Reporting duties survive end of support, unlike most of the CRA's other vulnerability-handling requirements, which means legacy product lines remain in scope. The CRA's requirement that manufacturers publish a coordinated vulnerability disclosure policy does not apply until December 2027.

What changed

The trigger is a reasonable degree of certainty that a vulnerability is being exploited or that an incident has severely compromised product security — a judgment call that must be made in hours, often on partial telemetry, and one that manufacturers cannot defer by declining to investigate.

Adobe confirmed this week that a maximum-severity Magento flaw, CVE-2026-75650, has been exploited against merchants since Sept.

Read: Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores

Why this matters

And the harmonised standards that will define what adequate compliance looks like are still working through public enquiry, so companies are building processes against a moving target.

The technical picture

Reporting duties survive end of support, unlike most of the CRA's other vulnerability-handling requirements, which means legacy product lines remain in scope.

The CRA's requirement that manufacturers publish a coordinated vulnerability disclosure policy does not apply until December 2027.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.

What remains unknown

The available reporting does not establish who is behind the activity, if an attacker is involved.

MORE IN VULNERABILITIES

More cybersecurity reporting

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 ReleasesSecurityWeek · 15 Sept 2026, 4:36 pm4 in 5 Singapore Business Websites Have WordPress VulnerabilitiesThe Cyber Express · 15 Sept 2026, 1:53 pmCisco Secure Email Gateway zero-day exploited to gain root command executionThe Hacker News · 15 Sept 2026, 11:41 am'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkDark Reading · 15 Sept 2026, 3:07 am