68

Recital 68

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

Quick Answer for Manufacturers

Recital 68 defines 'actively exploited vulnerabilities': cases where the manufacturer establishes that a security breach has resulted from malicious actors. This triggers the 24-hour early warning obligation under Article 14.

This quick answer + FAQ supplements the original legal text with practice-oriented interpretation. Only the original text is legally binding.

Actively exploited vulnerabilities concern instances where a manufacturer establishes that a security breach affecting its users or any other natural or legal persons has resulted from a malicious actor making use of a flaw in one of the products with digital elements made available on the market by the manufacturer. Examples of such vulnerabilities could be weaknesses in a product’s identification and authentication functions. Vulnerabilities that are discovered with no malicious intent for purposes of good faith testing, investigation, correction or disclosure to promote the security or safety of the system owner and its users should not be subject to mandatory notification. Severe incidents having an impact on the security of the product with digital elements, on the other hand, refer to situations where a cybersecurity incident affects the development, production or maintenance processes of the manufacturer in such a way that it could result in an increased cybersecurity risk for users or other persons. Such a severe incident could include a situation where an attacker has successfully introduced malicious code into the release channel via which the manufacturer releases security updates to users.

Common Manufacturer Questions

How does 'actively exploited' differ from a normal vulnerability?

An actively exploited vulnerability is not just theoretically possible but demonstrably attacked. Recital 68 says: a malicious actor uses a flaw in the product and causes a security breach affecting users.

Does a bug bounty finding count as active exploitation?

No. Vulnerabilities discovered in the course of security research, testing, or coordinated disclosure do not fall under mandatory reporting — provided no malicious exploitation has occurred. This is the critical distinction.

Who decides that a vulnerability is being actively exploited?

The manufacturer — based on available information. Telemetry, incident response data, and customer reports can be triggers. When in doubt: reporting precautionarily is safer than not reporting.

Related Articles

(1)

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex