Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is an actively exploited vulnerability under the CRA?
Updated
Under the CRA, an 'actively exploited vulnerability' is a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner (Article 3(42)). This page is not legal advice and does not start a clock.
CRA actively-exploited definition, last verified 9 September 2026 against Regulation (EU) 2024/2847 Articles 3(40)–(42), 14 and 71, the European Commission's CRA pages (last updated 7 September 2026) and 27 July 2026 guidance (guidance, not the regulation), and ENISA product-security / Single Reporting Platform materials (agency guidance, not the regulation). CISA's Known Exploited Vulnerabilities catalog and FIRST EPSS are contrast sources, not the regulation. It is not legal advice, not a filing, not a finding that YOUR CVE is actively exploited, and not a substitute for counsel.
This is the CRA definition, not YOUR CVE
Audience: an engineering leader, CISO, or compliance owner who needs the CRA trigger term — not a scanner label, not a US catalog, and not a severity band. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a named CVE is an actively exploited vulnerability contained in YOUR product with digital elements, that you have become aware, or that a filing is due.
The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. Article 3(42) is the definition this page quotes. Article 14(1) is the reporting trigger that uses that definition. This page does not apply those articles to YOU. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance versus industry terminology: Articles 3(40)–(42), 14 and 71 are legal requirements only if they apply. Commission CRA pages and the 27 July 2026 Commission guidance are Commission materials — guidance, not the regulation. ENISA product-security and Single Reporting Platform materials are agency guidance, not the regulation. CISA KEV, 'known exploited', 'exploited in the wild', CVSS, and EPSS are industry or third-country instruments. The CRA does not name them. This page quotes which kind of text it is relying on.
- The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The live Article 14 reporting guide on this site is the CRA Article 14 page under breach reporting.
- A dedicated 24-hour-early-warning, 72-hour-notification, final-report, vulnerability-management, and reporting-decision-tree guide in this CRA cluster is not on this site yet. Naming them is not a link.
Article 3(40)–(42) — three definitions, not one
Article 3 uses three nested words. They are not interchangeable. This page quotes them as the regulation states them. It does not find that YOUR CVE sits in any of the three. Last verified 9 September 2026. Not legal advice.
- Article 3(42) requires reliable evidence that exploitation has happened. It does not say 'critical CVSS'. It does not say 'high EPSS'. It does not say 'on CISA KEV'. It does not say 'known exploited'.
- Article 3(41) is a different class: potential under practical operational conditions. An exploitable vulnerability is not, by that fact alone, an actively exploited vulnerability.
- The CRA does not define 'reliable evidence' as a named catalog, a CVE identifier, or a score. Counsel maps YOUR facts to Article 3(42). This page does not run that test.
| Term | What Article 3 says | Kind of text | Last verified |
|---|---|---|---|
| Vulnerability — Article 3(40) | A weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat. | Legal requirement — Article 3(40). This page does not find that YOUR finding is a vulnerability of YOUR product. | 9 September 2026 |
| Exploitable vulnerability — Article 3(41) | A vulnerability that has the potential to be effectively used by an adversary under practical operational conditions. | Legal requirement — Article 3(41). Potential to be used is not the same as has been exploited. This page does not collapse 3(41) into 3(42). | 9 September 2026 |
| Actively exploited vulnerability — Article 3(42) | A vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. | Legal requirement — Article 3(42). This page does not find that YOUR CVE is actively exploited. | 9 September 2026 |
Article 14(1) — this trigger starts the actively-exploited track
Article 14(1): a manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7, and to ENISA, via the single reporting platform established pursuant to Article 16.
That sentence is the actively-exploited track. It is not the severe-incident track. Article 14(2) then sets a 24-hour early warning, a 72-hour notification, and a 14-day final report on this track. Those three marks are not one number. This page does not start that clock. Last verified 9 September 2026. Not legal advice.
- Article 14 applies from 11 September 2026 (Article 71(2)). Last verified 9 September 2026. This page does not start that clock.
- A dedicated 24-hour-early-warning, 72-hour-notification, and final-report guide in this CRA cluster is not on this site yet. Naming them is not a link. The live Article 14 reporting guide on this site is the ladder under breach reporting.
| Trigger | What the text says | Kind of text | Last verified |
|---|---|---|---|
| Actively exploited vulnerability — Article 14(1) | A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of, simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform. | Legal requirement — Article 14(1). Only if the CRA applies. Contained in the product is part of the sentence. | 9 September 2026 |
| Actively exploited vulnerability — definition used by that trigger | Article 3(42): a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner. | Legal requirement — Article 3(42). This page does not find that YOUR CVE meets it. | 9 September 2026 |
| Early warning / notification / final report on this track — Article 14(2) | Article 14(2)(a): 24-hour early warning from the manufacturer becoming aware. Article 14(2)(b): 72-hour notification from the same awareness. Article 14(2)(c): final report no later than 14 days after a corrective or mitigating measure is available. Those three marks are not one number. This page does not start 24 hours, 72 hours, or 14 days. | Legal requirement — Article 14(2). The live Article 14 reporting guide on this site is the ladder. | 9 September 2026 |
| Severe incident — Article 14(3) and 14(5) — a different trigger | Article 14(3): a manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of, via the same platform. Article 14(5) is a qualitative severe test. It is not Article 3(42). The severe-incident final report is one month after the 72-hour incident notification (Article 14(4)(c)), not 14 days. | Legal requirement — Article 14(3)–(5). Do not paste this trigger onto Article 3(42). | 9 September 2026 |
Comparison — CRA actively exploited versus KEV, known exploited, CVSS, and EPSS
Industry tools answer different questions. None of them is Article 3(42) unless the regulation says so. It does not. Last verified 9 September 2026. Not legal advice.
| Signal | Question it answers | Same as CRA Article 3(42)? | Kind of text | Last verified |
|---|---|---|---|---|
| CRA actively exploited vulnerability | Is there reliable evidence that a malicious actor has exploited this vulnerability in a system without permission of the system owner? | This is Article 3(42). Article 14(1) uses it, and only if the vulnerability is contained in the product with digital elements and the manufacturer becomes aware. | Legal requirement — Articles 3(42) and 14(1), only if the CRA applies. | 9 September 2026 |
| CISA Known Exploited Vulnerabilities (KEV) catalog | Has CISA listed this CVE on a US catalog of vulnerabilities with evidence of exploitation in the wild, a CVE identifier, and a clear remediation action? | No. The CRA does not name CISA or KEV. A KEV listing may be how you learn a fact. It is not, by itself, the legal finding that Article 3(42) is met, that the vulnerability is contained in YOUR product, or that you have become aware. | US catalog / CISA program. Contrast only — not the regulation. | 9 September 2026 |
| 'Known exploited' / 'exploited in the wild' | Industry shorthand, and the name of CISA's catalog. Not a defined term in Article 3. | No. The CRA's defined term is 'actively exploited vulnerability' in Article 3(42). Do not treat a blog, a scanner tag, or 'known exploited' talk as Article 3(42). | Industry terminology. Not the regulation. | 9 September 2026 |
| Critical CVSS | How severe would the flaw be if exploited? FIRST.org CVSS v3.x treats 9.0–10.0 as Critical. | No. CVSS scores intrinsic severity. Article 3(42) is evidence of exploitation that has happened. A critical score without that evidence is not Article 3(42). | FIRST.org scoring standard. Contrast only — not the regulation. | 9 September 2026 |
| EPSS-predicted | What is the model's estimated probability the vulnerability will be exploited in the wild in the next 30 days? | No. EPSS is a prediction of near-term likelihood. Article 3(42) is evidence that a malicious actor has already exploited it. A high EPSS is not that evidence. | FIRST.org Exploit Prediction Scoring System. Contrast only — not the regulation. | 9 September 2026 |
| CISA BOD 22-01 (US federal civilian agencies) | A US Binding Operational Directive that requires FCEB agencies to remediate KEV-listed vulnerabilities on CISA's due dates. | No. BOD 22-01 is not the CRA. A US federal remediation deadline is not an Article 14 clock. | US federal civilian directive. Contrast only — not the regulation. | 9 September 2026 |
Examples — contrasts, not YOUR filing decision
Whether Article 14(1) applies depends on counsel applying Articles 3(42) and 14 to YOUR facts. The rows below are contrasts. They are not a determination that YOU should or should not file. This page does not start a clock. Last verified 9 September 2026. Not legal advice.
| Situation | Is it Article 3(42) / Article 14(1) by itself? | What this page does not do | Kind of text |
|---|---|---|---|
| A CVE with a critical CVSS score and no evidence of exploitation | No. CVSS is not Article 3(42). Article 3(42) needs reliable evidence that a malicious actor has exploited it. | Does not score YOUR CVE. Does not start a clock. | Article 3(42) is the legal requirement. CVSS is contrast. |
| A CVE with a high EPSS score and no observed exploitation | No. EPSS predicts likelihood. Article 3(42) is evidence of exploitation that has happened. | Does not apply EPSS as the CRA test. | Article 3(42) is the legal requirement. EPSS is contrast. |
| A CVE listed on CISA KEV | Not by the listing alone. The CRA does not name KEV. A listing may be how you learn a fact. It is not automatic becoming-aware, and it is not a finding that the vulnerability is contained in YOUR product. | Does not treat a KEV row as Article 14 awareness. Does not start a clock. | Article 3(42) and 14(1) are the legal requirement. KEV is contrast. |
| Scanner or ticket tagged 'known exploited' or 'exploited in the wild' | Not by the tag alone. Those phrases are not Article 3 defined terms. | Does not treat a scanner tag as Article 3(42). | Industry terminology. Not the regulation. |
| An Article 3(41) exploitable vulnerability that has not been exploited | No. Potential to be used under practical operational conditions is not reliable evidence that a malicious actor has exploited it. | Does not collapse Article 3(41) into Article 3(42). | Legal requirement — Articles 3(41) and 3(42) are distinct. |
| A vulnerability in a component that is not contained in the product with digital elements | Article 14(1) is an actively exploited vulnerability contained in the product with digital elements. Containment is part of the sentence. This page does not find that YOUR product contains a named component. | Does not run the contained-in-the-product test for YOU. | Legal requirement — Article 14(1). |
| A severe incident having an impact on the security of the product (Article 14(5)) | That is a different Article 14 trigger. It is not Article 3(42). The severe-incident final report is one month after the 72-hour incident notification, not 14 days. | Does not score YOUR incident as severe. Does not start that clock. | Legal requirement — Article 14(3)–(5). |
| Reliable evidence of exploitation, contained in the product, manufacturer becomes aware — if the CRA applies | That is the Article 14(1) actively-exploited track as the article states it. The 24-hour / 72-hour / 14-day marks then follow Article 14(2). This page does not find that YOUR facts meet those tests. | Does not find that you have become aware. Does not start a clock. Does not file. | Legal requirement — Articles 3(42) and 14(1)–(2), only if the CRA applies. |
Legal requirement versus Commission, ENISA, and industry text
The table below labels each text. Do not treat a catalog as the article, and do not treat the article as optional because a catalog exists. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Articles 3(40)–(42), 14 and 71 | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU. Does not start a clock. |
| European Commission CRA policy page (updated 7 September 2026) and 27 July 2026 guidance (C(2026) 5252) | Commission materials. Guidance, not the regulation. | Does not treat a Commission FAQ as a substitute for Article 3(42). |
| ENISA product-security pages and Single Reporting Platform materials | Agency guidance on product security and the Article 16 platform. Not the regulation. | Does not treat an ENISA FAQ as starting YOUR clock, and does not treat an ENISA glossary as rewriting Article 3(42). |
| CISA KEV catalog and BOD 22-01 | US catalog and US federal civilian directive. Contrast only. | Does not treat a KEV row as Article 3(42) or as becoming aware. |
| FIRST.org CVSS and EPSS | Severity scoring and exploitation-probability model. Contrast only. | Does not treat a critical CVSS or a high EPSS as Article 3(42). |
What to do now
As of last verification on 9 September 2026, Article 14 applies from 11 September 2026 — two days from that verification date. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that a named CVE is actively exploited, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. The who-is-covered guide on this site is the roles page. Marking CRA in an obligation map is not that determination.
- Ask counsel whether a named vulnerability is an Article 3(42) actively exploited vulnerability contained in that product, and whether the manufacturer has become aware. Do not treat a KEV listing, a critical CVSS, a high EPSS, or a scanner tag as that finding.
- If counsel says Article 14(1) may apply, open the live Article 14 reporting guide on this site for the 24-hour / 72-hour / 14-day ladder. This page does not start that clock.
- Do not paste the severe-incident trigger onto Article 3(42). Do not treat Commission, ENISA, or CISA text as the regulation.
- A dedicated 24-hour-early-warning, 72-hour-notification, final-report, vulnerability-management, and reporting-decision-tree guide in this CRA cluster is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a filing, and not YOUR CVE determination. Walk it with counsel. The live Article 14 reporting guide on this site is the ladder. The reporting-deadlines page on this site is the statute table of clocks.
- Does the CRA apply? Product with digital elements made available on the Union market — Articles 2 and 3. This page does not run that test.
- Is the finding a vulnerability (Article 3(40)), an exploitable vulnerability (Article 3(41)), or an actively exploited vulnerability (Article 3(42))? Those three are not one word.
- Is there reliable evidence that a malicious actor has exploited it in a system without permission of the system owner? This page does not weigh YOUR evidence.
- Is it contained in the product with digital elements (Article 14(1))? This page does not run that containment test.
- Is CISA KEV the same as CRA actively exploited? No. The regulation does not name KEV.
- Is a critical CVSS or a high EPSS the CRA trigger? No.
- Is a severe incident the same trigger? No — Article 14(3) and 14(5) are a different track.
- Article 14 from 11 September 2026: 24-hour early warning, 72-hour notification, 14-day final report on the actively-exploited track. This page does not start that clock.
- Document the assessment, including a not-this-trigger decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that the CRA applies, does not decide that you are a manufacturer, does not decide that a CVE is an actively exploited vulnerability under Article 3(42), does not start an Article 14 clock, and does not submit to ENISA or a CSIRT. None of the surfaces below is 'this CVE is actively exploited', 'this clock has started', or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That tracker does not start an Article 14 clock, does not decide that the CRA applies, does not decide that a CVE is actively exploited, and does not file with a CSIRT or ENISA. A KEV match timestamp is disclosure, not the clock. Recorded awareness is a human determination the platform must not backdate. A named human still submits.
The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. Marking cra in-scope is not a finding that every security finding is an actively exploited vulnerability, and is not a determination that you are a manufacturer. The cyber risk register lives under Security. It is not an Article 14 file. The CISA KEV glossary on this site is the US catalog, not Article 3(42).
This page does not document a public demo URL. There is no public CRA demo path.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 3(40)–(42), 14 and 71, is a legal requirement only if it applies. Article 14 applies from 11 September 2026 (Article 71(2)). The European Commission's CRA policy page (updated 7 September 2026) and 27 July 2026 guidance (C(2026) 5252) are Commission materials, not the regulation. ENISA's product-security pages and Single Reporting Platform materials are agency guidance, not the regulation. CISA's Known Exploited Vulnerabilities catalog and BOD 22-01 are US materials, cited for contrast only. FIRST.org CVSS and EPSS are scoring and prediction models, cited for contrast only. These are not a complete world list. Not legal advice.
The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The CRA Article 14 reporting guide on this site is the live ladder. The reporting-deadlines page on this site is the statute table of clocks. The CISA KEV glossary on this site is the US catalog. The CVSS glossary and the EPSS glossary on this site are the scoring models. A dedicated 24-hour-early-warning, 72-hour-notification, final-report, vulnerability-management, and reporting-decision-tree guide in this CRA cluster is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a definition page distilled from Regulation (EU) 2024/2847 Articles 3(40)–(42) and 14, with Commission and ENISA materials labelled as guidance, not the regulation, and with CISA KEV, CVSS, and EPSS labelled as contrast. Whether a named CVE is an actively exploited vulnerability contained in YOUR product, and whether you have become aware, are legal and factual questions for counsel on your facts. This page does not start a clock.
Does ShipReady decide a vulnerability is actively exploited?
No. The signed-in app does not decide that a CVE is an actively exploited vulnerability under Article 3(42). Compliance → CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. A KEV match timestamp is disclosure, not the clock. That tracker does not file, and does not start a clock. A named human still submits.
Is CISA KEV the same as CRA actively exploited?
No. The CRA does not name the CISA Known Exploited Vulnerabilities catalog. Article 3(42) is a Union-law definition: reliable evidence that a malicious actor has exploited the vulnerability in a system without permission of the system owner. A KEV listing may be how you learn a fact. It is not, by itself, the legal finding, not automatic becoming-aware, and not a finding that the vulnerability is contained in YOUR product.
Does marking CRA in-scope mean every finding is actively exploited?
No. Marking the bundled framework key cra in-scope on the obligation map is not a finding that every security finding is an actively exploited vulnerability. The CRA ladder in this product applies only to findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That mark is not Article 3(42), not a manufacturer determination, and not a clock start.
Is a critical CVSS score the CRA actively-exploited trigger?
No. CVSS rates how severe a flaw would be if exploited. Article 3(42) is reliable evidence that a malicious actor has already exploited it. A critical score without that evidence is not the Article 14(1) trigger. EPSS is also not that trigger — it predicts near-term likelihood, it does not record exploitation that has happened.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.