InsideCRA
InsideCRA › Definitions › Actively exploited vulnerability

Defined term

Actively exploited vulnerability

One of the two reporting triggers, with a 24-hour fuse.

LAW Defined in Article 3 (Art. 3(42)). The verbatim definition is in the official text of Article 3; only the Official Journal is authentic.

BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847

An actively exploited vulnerability is one for which there is reliable evidence that a malicious actor has exploited it in a system without the system owner's permission F-030. It is one of the two Article 14 triggers, and from 11 September 2026 it starts a 24-hour early-warning clock on awareness F-002 F-028.

The definitional edge that matters: exploitation evidence, not severity, is the trigger F-030 — a low-CVSS bug being exploited reports; a critical bug nobody has touched does not, under this limb.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Not sure whether this applies to your product? Check if the CRA applies to you on CRARequired.