Kilde › Guides › CRA › “Actively exploited vulnerability” vs …
Current to 26 August 2026 · updates land in the changelog.
Everything in the CRA's reporting machine hangs off two defined triggers. Get the trigger analysis wrong and you either miss a mandatory 24-hour clock or file reports the law never asked for — both expensive in their own way.
An actively exploited vulnerability is one where there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner (Article 3(42)). Three load-bearing elements: reliable evidence, actual exploitation, absence of permission.
The neighbouring defined term is the trap: an exploitable vulnerability (Article 3(41)) — one that can be exploited — does not trigger Article 14 reporting by itself. A pen-test finding or a scary CVSS score creates vulnerability-handling work under Annex I Part II, but the 24-hour reporting clock starts only when exploitation is actually happening.
Article 14(5) defines a severe incident having an impact on the security of the product as one that: (a) negatively affects — or is capable of negatively affecting — the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or (b) has led, or is capable of leading, to the introduction or execution of malicious code in the product or in the network and information systems of a user.
Note the reach of “capable of”: both limbs cover credible near-misses, not only materialised harm. That makes the severity assessment a judgement call worth pre-structuring — a written triage worksheet beats an ad-hoc call at 2 a.m.
The two tracks share the 24-hour and 72-hour rhythm but diverge at the final report — 14 days after a corrective measure is available on the vulnerability track, one month after the 72-hour notification on the incident track — and their required content differs at every stage. Triage is therefore not paperwork: it decides your deadlines.
The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.
Get the pack — US$390 Free 4-page sample (PDF)Instant download · 14-day unconditional refund · single-organisation licence · full product page
General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com