ENISA, the EUVD, and CRA reporting
ENISA operates the reporting and vulnerability infrastructure at the centre of the Cyber Resilience Act. Here is how each touchpoint works and how the platform aligns with it.
ENISA's role under the CRA
Under Article 14 of the Cyber Resilience Act, a manufacturer that becomes aware of an actively exploited vulnerability in a product with digital elements must notify the coordinating CSIRT and ENISA through a single reporting platform. An early warning is due within 24 hours, a fuller notification within 72 hours, and a final report once the vulnerability is handled. ENISA also runs the European Vulnerability Database, the EU's public record of critical and exploited vulnerabilities.
CVD Portal is an independent platform and is not affiliated with or endorsed by ENISA or the EU. It aligns with these touchpoints so a manufacturer can meet the obligation with less manual effort.
ENISA also publishes engineering guidance, separately from its reporting infrastructure role. The Secure by Design and Default Playbook is 22 playbooks covering product security across the life cycle, mapped there to the Annex I requirements each one evidences.
Getting access to the SRP
ENISA published the operational guidance for the Single Reporting Platform on 31 July 2026, as separate documents covering authorised-representative user registration and notification submission, plus a two-page reporting factsheet. Three points from it change how manufacturers should prepare.
- Access runs through EU Login. You sign in to the platform with a European Commission EU Login account, and the account can be created now. This applies to manufacturers and to the authorised representatives of open-source software stewards alike.
- Your coordinating CSIRT validates your reporters. ENISA states that the CSIRT designated as coordinator confirms that a representative may submit on behalf of a specific manufacturer, and that this happens after first access rather than as a box you can tick in advance.
- There is no submission API. ENISA states that no application programming interfaces will be provided at this stage. Every notification is filed by a person, inside a 24-hour window that can open at any hour.
The platform is scheduled to be operational by 11 September 2026, the same day the reporting obligation starts to apply, so there is no period in which to learn it under no pressure. ENISA SRP guidance and FAQ.
Touchpoints and platform alignment
ENISA Single Reporting Platform
Where manufacturers file the Article 14 notifications for actively exploited vulnerabilities and severe incidents.
The platform runs the full Article 14 cascade: early warning within 24 hours, notification within 72 hours, and a final report, each with its own deadline timer. It generates a pre-filled ENISA submission package ready to paste into the Single Reporting Platform.
European Vulnerability Database (EUVD)
ENISA's public database of vulnerabilities, including critical and actively exploited entries.
CVD Portal pulls the live EUVD feeds directly from ENISA and uses them for monitoring and impact assessment against your SBOM. The feed below is the same source.
National CSIRTs
The Article 14 notification also goes to the CSIRT designated as coordinator in the manufacturer's member state.
The platform derives the correct national CSIRT and its Article 14 contact from a per-country directory, so the notification is routed to the right coordinator.
CSAF 2.0 advisories
Machine-readable security advisories that align with the EU move toward automated vulnerability information exchange.
CVD Portal generates CSAF 2.0 VEX advisories and publishes a provider metadata feed, so disclosures are machine-readable for downstream consumers.
EU Vulnerability Database (EUVD) Pulse
Official feed of the latest critical and actively exploited vulnerabilities tracked by European authorities.
Latest Critical Vulnerabilities
CVSS 9.0+** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Lucy is now maintained outside of the ASF at https://github.com/lucysearch . This issue has been fixed in 0.8.0 there. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. Lucy is now maintained outside of the ASF at https://github.com/lucysearch . 0.8.0 is no longer affected by this issue, because the offending feature has been removed there. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it outright and revoke the victim agent's cluster monitoring access.
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
Actively Exploited (KEV)
In the wildGeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving arbitrary command execution as the GeoNetwork process user. A user with sufficient privileges to upload a formatter can deliver a `.xsl` file containing Java extension call that execute arbitrary OS commands with the privileges of the GeoNetwork process. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files into the GeoNetwork formatter directory. On its own this constitutes unauthorized write access to server storage. The issue is patched in GeoNetwork versions 4.4.12 and 4.2.17.
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Be ready for the 24-hour clock
Run Article 14 reporting with deadline timers and a pre-filled ENISA submission package.