Definition
Actively exploited vulnerability
A vulnerability for which there is reliable evidence that malicious code was executed on a system without the owner's permission — the trigger for Article 14 reporting.
A vulnerability for which there is reliable evidence that execution of malicious code was performed by an actor on a system without the permission of the system owner. Reliable evidence may come from the manufacturer's own telemetry, a customer report, a researcher, a CSIRT or an exploitation catalogue such as CISA KEV. Once the manufacturer becomes aware, Article 14 requires an early warning within 24 hours, a notification within 72 hours and a final report within 14 days of a corrective measure becoming available.
Reference: Art. 3(42); Art. 14(1)–(3) · Regulation (EU) 2024/2847 on EUR-Lex
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.