← All standards
ENISACRA Article 14

ENISA, the EUVD, and CRA reporting

ENISA operates the reporting and vulnerability infrastructure at the centre of the Cyber Resilience Act. Here is how each touchpoint works and how the platform aligns with it.

ENISA's role under the CRA

Under Article 14 of the Cyber Resilience Act, a manufacturer that becomes aware of an actively exploited vulnerability in a product with digital elements must notify the coordinating CSIRT and ENISA through a single reporting platform. An early warning is due within 24 hours, a fuller notification within 72 hours, and a final report once the vulnerability is handled. ENISA also runs the European Vulnerability Database, the EU's public record of critical and exploited vulnerabilities.

CVD Portal is an independent platform and is not affiliated with or endorsed by ENISA or the EU. It aligns with these touchpoints so a manufacturer can meet the obligation with less manual effort.

Touchpoints and platform alignment

ENISA Single Reporting Platform

Where manufacturers file the Article 14 notifications for actively exploited vulnerabilities and severe incidents.

The platform runs the full Article 14 cascade: early warning within 24 hours, notification within 72 hours, and a final report, each with its own deadline timer. It generates a pre-filled ENISA submission package ready to paste into the Single Reporting Platform.

European Vulnerability Database (EUVD)

ENISA's public database of vulnerabilities, including critical and actively exploited entries.

CVD Portal pulls the live EUVD feeds directly from ENISA and uses them for monitoring and impact assessment against your SBOM. The feed below is the same source.

National CSIRTs

The Article 14 notification also goes to the CSIRT designated as coordinator in the manufacturer's member state.

The platform derives the correct national CSIRT and its Article 14 contact from a per-country directory, so the notification is routed to the right coordinator.

CSAF 2.0 advisories

Machine-readable security advisories that align with the EU move toward automated vulnerability information exchange.

CVD Portal generates CSAF 2.0 VEX advisories and publishes a provider metadata feed, so disclosures are machine-readable for downstream consumers.

EU Vulnerability Database (EUVD) Pulse

Official feed of the latest critical and actively exploited vulnerabilities tracked by European authorities.

Latest Critical Vulnerabilities

CVSS 9.0+
EUVD-2025-18415CVSS 9.1

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.

6/16/2025redhat
EUVD-2025-18412CVSS 9.1

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.

6/16/2025redhat
EUVD-2026-6910CVSS 9.2

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerability by supplying a malicious JSON Path expression that, when evaluated, executes arbitrary JavaScript code, leading to Remote Code Execution in Node.js environments or Cross-site Scripting (XSS) in browser contexts. This affects all methods that evaluate JSON Paths against objects, including .query, .nodes, .paths, .value, .parent, and .apply.

2/9/2026snyk
EUVD-2026-52004CVSS 9.3

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.

8/2/2026VulnCheck

Actively Exploited (KEV)

In the wild
EUVD-2026-50404CVSS 5.3

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.&nbsp; Note:&nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&nbsp;&nbsp; Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Exploited: 7/29/2026Cisco
EUVD-2025-207440CVSS 5.3

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Exploited: 7/27/2026Fortinet
EUVD-2026-49334CVSS 10

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

Exploited: 7/27/2026Arista Networks
EUVD-2026-47700CVSS 9.3

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Exploited: 7/22/2026checkpoint

Be ready for the 24-hour clock

Run Article 14 reporting with deadline timers and a pre-filled ENISA submission package.