The Cyber Resilience Act's vulnerability reporting duties are already in force, well before the December 2027 date that governs most of the regulation, and they sit alongside five other disclosure regimes whose clocks start differently.
Perspective Coverage
5 publishers
- Builder
- Builder 36%
- Operator
- Operator 50%
- Investor
- Investor 14%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence72
Syft and Trivy reported 43.78% and 32.71% of lockfile packages across 2,050 JavaScript repositories in an Inria and ANSSI study, against 98.72% for cdxgen. The tool, its version and its flags decide what an SBOM lists, so that recipe belongs under version control.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
TECH VEDA counts 36 actionable device CVEs across 14 non-kernel packages in September, two of them Chromium V8 bugs on CISA's exploited list. How many apply to a given fleet depends on each image's SBOM and on which scorer a team trusts.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
EU Cyber Resilience Act manufacturers have had to report actively exploited vulnerabilities since September 11, before broader duties arrive in December 2027. The New Stack argues those reports hold up only if engineers can already name the affected versions, components and fixes.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence45
BH Consulting launched BH Haven, a four-tier SME service in which a proprietary AI tool drafts findings and consultants approve them. CEO Brian Honan said using AI internally does not move the firm's contractual responsibility for a missed gap onto the software.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence40
EU Cyber Resilience Act rules have required 24-hour ENISA warnings on exploited flaws in commercial container images since Sept. 11, 2026. Vendors of supported Kubernetes operators and Helm charts are on the same clock, well before the rest of the law is enforced in December 2027.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.
Perspective Coverage
3 publishers
- Builder
- Builder 15%
- Operator
- Operator 73%
- Investor
- Investor 12%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives35
- Confidence60
CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.
Perspective Coverage
8 publishers
- Builder
- Builder 19%
- Operator
- Operator 73%
- Investor
- Investor 8%
Reality
- Evidence78
- Adoption45
- Hype gap+18
- Incentives30
- Confidence72
Microsoft fixed 974 flaws in September and two were already under attack, but both need an attacker who is already on the machine, while the twenty bugs Dustin Childs classes as wormable need no login at all.
Reality
- Evidence74
- Adoption58
- Hype gap+14
- Incentives60
- Confidence71
Administrator access on Mathspace's self-hosted reporting tool needed no login, and the week's other exposures sat in an unclaimed Elasticsearch cluster and inside an AI provider's shared package cache.
Reality
- Evidence38
- Adoption55
- Hype gap+12
- Incentives45
- Confidence45
Two or three of the 95 were genuine, and reviewers had to read all of them to find out. The EU's 24-hour ENISA clock starts on September 11, 2026, and only evidence of active exploitation starts it.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+35
- Incentives88
- Confidence62
The provenance on @7nohe/openapi-react-query-codegen was accurate about every question it was built to answer, which is why the Docker Security Dispatch reaches instead for a five-day resolution cooldown that npm ci does not apply.
Reality
- Evidence47
- Adoption
- Insufficient
- Hype gap+12
- Incentives72
- Confidence55
The EU Cyber Resilience Act starts the notification clock the moment a manufacturer learns a flaw is being exploited, making SBOM accuracy an operational deadline as much as a compliance requirement.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+35
- Incentives82
- Confidence52
EU Cyber Resilience Act enforcement starts in September with personal liability for security leaders written in, according to JFrog, so the lag between an auditor's request and the proof now has a named owner.
Reality
- Evidence24
- Adoption12
- Hype gap+46
- Incentives92
- Confidence58
Manufacturers selling into the EU owe a regulator notice within 24 hours of learning that a product flaw is being exploited, while the design rules that would produce the records needed to answer arrive 456 days later.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence48
Traefik Labs argues most CVEs in a container come from the OS packaging around the application, not the application. Its pitch is attack surface reduction rather than faster detection.
Reality
- Evidence27
- Adoption
- Insufficient
- Hype gap+38
- Incentives82
- Confidence34
A one-person project translates Go's scheduler, channels, net/http and crypto/tls into Rust with no GC, no glibc and no Tokio, and stamps every function with its Go source line.
Reality
- Evidence30
- Adoption6
- Hype gap+38
- Incentives68
- Confidence42