Defined term
Actively exploited vulnerability
One of the two reporting triggers, with a 24-hour fuse.
LAW Defined in Article 3 (Art. 3(42)). The verbatim definition is in the official text of Article 3; only the Official Journal is authentic.
sha256:27b7c6c64c773001… · CELEX 32024R2847An actively exploited vulnerability is one for which there is reliable evidence that a malicious actor has exploited it in a system without the system owner's permission F-030. It is one of the two Article 14 triggers, and from 11 September 2026 it starts a 24-hour early-warning clock on awareness F-002 F-028.
The definitional edge that matters: exploitation evidence, not severity, is the trigger F-030 — a low-CVSS bug being exploited reports; a critical bug nobody has touched does not, under this limb.
Verified facts this page relies on
- F-030 Actively exploited vulnerability (Art. 3(42)): reliable evidence that a malicious actor has exploited it in a system without the system owner's permission. A severe incident having an impact on the security of the product (Art. 14(5)) is one that negatively affects or is capable of negatively affecting the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led or is capable of leading to the introduction or execution of malicious code. Art. 3(42), Art. 3(44), Art. 14(5)
- F-028 Actively exploited vulnerability: early warning within 24 hours of awareness; notification within 72 hours; final report within 14 days after a corrective or mitigating measure is available. Art. 14(1)–(2)
- F-002 Article 14 (reporting obligations of manufacturers) applies from 11 September 2026. Art. 71(2)
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Related in the reference
- Topic: Article 14 reporting
- Article 14 — Reporting obligations of manufacturers
- Definition: Severe incident having an impact on the security of the product