Definition

Actively exploited vulnerability

A vulnerability for which there is reliable evidence that malicious code was executed on a system without the owner's permission — the trigger for Article 14 reporting.

A vulnerability for which there is reliable evidence that execution of malicious code was performed by an actor on a system without the permission of the system owner. Reliable evidence may come from the manufacturer's own telemetry, a customer report, a researcher, a CSIRT or an exploitation catalogue such as CISA KEV. Once the manufacturer becomes aware, Article 14 requires an early warning within 24 hours, a notification within 72 hours and a final report within 14 days of a corrective measure becoming available.

Reference: Art. 3(42); Art. 14(1)–(3) · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-12 · Paraphrase for orientation, not legal advice.

In practice

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.