Skip to content

standard

EU Cyber Resilience Act

EU regulation requiring cybersecurity standards for hardware and software sold in the EU, with 24-hour reporting of exploited flaws.

Known aliases

  • CRA
  • Cyber Resilience Act
  • EU CRA

Relationships

No evidence-backed relationships are recorded.

Current stories

security5 publishers

Manufacturers selling into the EU now owe ENISA a 24-hour warning on exploited flaws

The Cyber Resilience Act's vulnerability reporting duties are already in force, well before the December 2027 date that governs most of the regulation, and they sit alongside five other disclosure regimes whose clocks start differently.

Publishers:commission.europa.eucsoonline.comdev.toscworld.comwebflow.sysdig.com

Perspective Coverage

5 publishers
Builder
Builder 36%
Operator
Operator 50%
Investor
Investor 14%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives55
Confidence72
security1 publisher

EU's Cyber Resilience Act puts Helm chart and Kubernetes operator vendors on a 24-hour exploit clock

EU Cyber Resilience Act rules have required 24-hour ENISA warnings on exploited flaws in commercial container images since Sept. 11, 2026. Vendors of supported Kubernetes operators and Helm charts are on the same clock, well before the rest of the law is enforced in December 2027.

Reality

Evidence50
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence55
security3 publishers

Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says

watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.

Perspective Coverage

3 publishers
Builder
Builder 15%
Operator
Operator 73%
Investor
Investor 12%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence60
security8 publishers

Exposed MikroTik SSH hands over full administrative control without authentication

CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.

Perspective Coverage

8 publishers
Builder
Builder 19%
Operator
Operator 73%
Investor
Investor 8%

Reality

Evidence78
Adoption45
Hype gap+18
Incentives30
Confidence72