Published October 1, 2026 · Added October 1, 2026

The EU Is About to Make Linux's Vulnerability Management Problem Harder to Ignore

FOSS Force looks at how a surge in published CVEs, 48,244 in 2025 and 35,885 in the first half of 2026, is colliding with the EU Cyber Resilience Act's first reporting duties, which took effect September 11 and require manufacturers to report actively exploited vulnerabilities within 24 hours, with fuller notifications at 72 hours and a final report within 14 days of a fix. It notes the CRA deliberately exempts non-commercial open source development and gives open source stewards a lighter regime, but argues companies shipping commercial products built on open source still have to know what is inside them and be able to show what they patched, pointing to Debian's Security Tracker, Rocky Linux errata, and AlmaLinux advisories as practical starting points.

FOSS Force looks at how a surge in published CVEs, 48,244 in 2025 and 35,885 in the first half of 2026, is colliding with the EU Cyber Resilience Act’s first reporting duties, which took effect September 11 and require manufacturers to report actively exploited vulnerabilities within 24 hours, with fuller notifications at 72 hours and a final report within 14 days of a fix. It notes the CRA deliberately exempts non-commercial open source development and gives open source stewards a lighter regime, but argues companies shipping commercial products built on open source still have to know what is inside them and be able to show what they patched, pointing to Debian’s Security Tracker, Rocky Linux errata, and AlmaLinux advisories as practical starting points.

Read the original story.

Source: FOSS Force