EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act
Manufacturers selling connected products in the European Union face a new legal duty starting Sept.

Manufacturers selling connected products in the European Union face a new legal duty starting Sept. Report actively exploited vulnerabilities to authorities within 24 hours of confirming them. The obligation arrives 15 months ahead of the Cyber Resilience Act's full application date of Dec. The CRA covers products with digital elements placed on the EU market, a category broad enough to take in enterprise software, consumer IoT devices, industrial controllers and much of the component software beneath them.
And the harmonised standards that will define what adequate compliance looks like are still working through public enquiry, so companies are building processes against a moving target.
Reporting duties survive end of support, unlike most of the CRA's other vulnerability-handling requirements, which means legacy product lines remain in scope. The CRA's requirement that manufacturers publish a coordinated vulnerability disclosure policy does not apply until December 2027.
What changed
The trigger is a reasonable degree of certainty that a vulnerability is being exploited or that an incident has severely compromised product security — a judgment call that must be made in hours, often on partial telemetry, and one that manufacturers cannot defer by declining to investigate.
Adobe confirmed this week that a maximum-severity Magento flaw, CVE-2026-75650, has been exploited against merchants since Sept.
Read: Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores
Why this matters
And the harmonised standards that will define what adequate compliance looks like are still working through public enquiry, so companies are building processes against a moving target.
The technical picture
Reporting duties survive end of support, unlike most of the CRA's other vulnerability-handling requirements, which means legacy product lines remain in scope.
The CRA's requirement that manufacturers publish a coordinated vulnerability disclosure policy does not apply until December 2027.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.
Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.
What remains unknown
The available reporting does not establish who is behind the activity, if an attacker is involved.