Skip to content
DS Content

Magazine for digital signage and DOOH

Glossary A–ZLetter V

Vulnerability reporting

Vulnerability reporting means notifying a security flaw in a product, either from outside to the manufacturer, for example by security researchers or customers, or from the manufacturer to the competent bodies.

There are now fixed rules for both directions.

Manufacturers set up a reporting point, usually an email address with a described procedure, and publish it; a file called security.txt on the website makes the address discoverable by machines. Under the Cyber Resilience Act, manufacturers have since 11 September 2026 had to report actively exploited vulnerabilities via a single reporting platform of the EU Agency for Cybersecurity (ENISA): an early warning within 24 hours, a notification within 72 hours and later a final report. Similar rules apply to severe security incidents.

What matters to operators is knowing where to report a flaw they discover and how quickly they will get a response. A coordinated disclosure policy determines when a flaw is made public, usually only once an update is available. A vulnerability is not yet an attack; under the regulation it only has to be reported once it is being actively exploited. A manufacturer without a reporting point will struggle to meet the short deadlines.

See also