Actively exploited vulnerability
A security vulnerability in your software or product that is known to be actively exploited. Even a single proven attack that exploits a vulnerability triggers Article 14 reporting requirement.
Starting September 11, 2026, the CRA Article 14 requires software maintainers to report actively exploited vulnerabilities and severe incidents to the EU within 24 hours of becoming aware of them. Patchstack provides known exploited vulnerability tracking & managed Article 14 reporting to EU for free.

Starting from 11th of September 2026, the EU Cyber Resilience Act requires manufacturers of software and connected products to report two things: vulnerabilities that attackers are actively exploiting, and severe security incidents affecting their products.
A security vulnerability in your software or product that is known to be actively exploited. Even a single proven attack that exploits a vulnerability triggers Article 14 reporting requirement.
An incident such as supply chain compromise or any other severe incident that affects the product availability, authenticity, integrity or that leads to malicious code running in your product or user's system.
Submitted through ENISA, naming the affected EU member states where your product is available.
Covers the product affected, the nature of the exploit, corrective or mitigating measures taken, and what users have to do to stay safe.
Details severity, impact, any known malicious actor, and the specifics of the fix.
States whether you suspect unlawful or malicious acts behind the incident.
Includes an initial assessment of the incident and the mitigation measures taken.
Covers the incident in detail — root cause, and mitigations applied.
The Cyber Resilience Act Article 14 applies to manufacturers and open source stewards of products/software made available on the EU market. Non-compliance penalties equal to GDPR penalties. Open source stewards are exempt from penalties however EU can still use other means necessary to remove a non-compliant product from the European market.
Patchstack provides a free-to-access platform for open-source maintainers that:


Software vendors can submit Patchstack as their assigned representative for security reporting:
If you have questions, don't hesitate to reach out via mvdp@patchstack.com.