(c)
Cyber Resilience Act
unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following: a description of the vulnerability, including its severity and impact; where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability; details about the security update or other corrective measures that have been made available to remedy the vulnerability.
← (b) · All articles · (i) →
Source: EUR-Lex CELLAR · retrieved 2026-09-04 · Text as adopted (Official Journal); later amendments are not incorporated in this text.