ctipilot.ch

EU Cyber Resilience Act

policy · policy:eu-cyber-resilience-act single-sourcesingle-source-national-cert

EU product-security regulation; first hard deadline (designation of notifying authorities) fell on 11 June 2026, with the CRA Single Reporting Platform following on 11 September 2026. Tracked for its direct compliance impact on European software and hardware vendors.

Aliases: CRA

Coverage timeline
28
first 2026-05-04 → last 2026-08-16
Peak priority
high
1 high · 27 notable
Sources cited
96
71 hosts
Sections touched
5
active-threats, research, weekly-annual-reports
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

Affected products
PTC WindchillAlibaba fastjsonFreeBSDGeoServerIBM WebSphere Application ServerLangflowMicrosoft Defender AntivirusPhoenix Contact CHARX SEC-3000Ruby on Rails Active StorageSiemens Desigo CCTrueNAS Enterprise

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1498Network Denial of Service×1

Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-06-14/looking-ahead-2026-w24 · ATT&CK page ↗

T1499Endpoint Denial of Service×1

Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-06-14/looking-ahead-2026-w24 · ATT&CK page ↗

Story timeline

  1. 2026-08-162026-W33 looking ahead — items already in motion: a CRA reporting clock at four weeks, standards approval that will not beat it, an exploited flaw with no patch in existence, seven further flaws with no fix coming, and twelve thousand Polish clinics who each owe a notification
    weekly-looking-aheadW33 outlook — the 11 September CRA reporting start, GeoServer exploited with no vendor fix, and a notification duty split across 12,000 controllers
  2. 2026-08-16UPDATE — the Cyber Resilience Act's conformity route entered formal approval this week: ETSI put 17 draft product-category standards out for Public Enquiry, and the procedure runs past the regulation's first reporting deadline
    weekly-policyETSI opens approval on 17 CRA standards covering firewalls, VPNs, SIEM and PKI software — none can be relied on before 11 September
  3. 2026-08-092026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out
    weekly-looking-aheadW32 outlook — the 15 August Dutch NIS2 clock, WALLIX details due in September, and five products with no fix coming
  4. 2026-08-022026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks
    weekly-looking-aheadW31 outlook — the 12 August CHARX firmware deadline, WebSphere on interim fixes, and Cl0p's pending listings
  5. 2026-08-02The European Commission published its first official Cyber Resilience Act application guidance six weeks before the regulation's reporting obligations begin — clarifying which products are in scope, including remote data processing and free and open-source software
    weekly-policyCommission issues first CRA application guidance, six weeks before the CRA reporting obligations start
  6. 2026-07-262026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tightening
    weekly-looking-aheadW30 outlook — the nginx RCE PoC clock, Oracle Fusion Middleware abuse 'very likely', a public Certighost AD CS PoC, a pending Mitel CVE, and the CRA/NIS2 clocks
  7. 2026-07-26ENISA moved cyber-assurance into procurement leverage this week — a public consultation on a mandatory EU Managed Security Services certification, and concrete hospital-procurement security guidance under a new Health Action Plan
    weekly-policyTwo ENISA moves turn guidance into procurement gates — a mandatory EUMSS certification for Reserve providers, and EU hospital-procurement security rules
  8. 2026-07-192026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks running
    weekly-looking-aheadW29 outlook — public PoCs (WP2Shell, Firefox), a SharePoint chain half-patched until August, a withheld ShareFile CVE, and the CRA/CER clocks already ticking
  9. 2026-07-19EU critical-entity and product-resilience regulation reached concrete operator-facing milestones this week — ENISA shipped a CRA readiness self-assessment ahead of the 11 September reporting clock, and Germany's KRITIS-Dachgesetz opened its first CER-Directive registration window
    weekly-policyTwo EU CI-resilience clocks advanced — ENISA's SME CRA maturity model ahead of the 11 Sept Article 14 duty, and Germany's KRITIS-Dachgesetz registration window
  10. 2026-07-12Looking ahead — 2026-W28
    weekly-looking-aheadLooking ahead — 2026-W28: items already in motion for the coming weeks
  11. 2026-06-29Looking ahead — 2026-W26
    weekly-looking-ahead
  12. 2026-06-29EU Cyber Resilience Act — 75 days to the 11 September vulnerability/incident-reporting obligation
    weekly-policy
  13. 2026-06-22Looking ahead — 2026-W25
    weekly-looking-ahead
  14. 2026-06-22G7 Évian cybersecurity declaration calls PQC an "urgent priority" — and the expected hacktivist DDoS materialised on day one
    weekly-policy
  15. 2026-06-22CRA reporting obligation lands 11 September — ENISA Single Reporting Platform access manual due, dry-runs before go-live
    weekly-policy
  16. 2026-06-14Looking ahead — 2026-W24
    weekly-looking-ahead
  17. 2026-06-14Germany's Bundestag opens first reading of the CRA domestic-implementation bill
    weekly-policy
  18. 2026-06-14ENISA publishes the first EU-wide SBOM Adoption State of Play — consumption lags generation
    weekly-policy
  19. 2026-06-10EU Cyber Resilience Act reaches its first hard deadline — notifying-authority designation due 11 June
    active-threats
  20. 2026-06-01Looking ahead — 2026-W23
    weekly-looking-ahead
  21. 2026-06-01CRA June 11 notifying-authority deadline — first hard CRA milestone with ENISA SRP manual and Secure Update Mechanisms advisory published
    weekly-policy
  22. 2026-05-25EU Cyber Resilience Act — 11 June notifying-authority deadline, then September reporting obligations
    weekly-policy
  23. 2026-05-11Verizon DBIR 2026 (19th annual edition)
    weekly-annual-reports
  24. 2026-05-11Looking ahead — 2026-W20
    weekly-looking-ahead
  25. 2026-05-11EU CRA milestones — 11 June 2026 CAB notification, 11 September 2026 Article 14 reporting obligations
    weekly-policy
  26. 2026-05-09ENISA expands CVE Root: four new European organisations onboarded as CVE Numbering Authorities
    research
  27. 2026-05-04EU Cybersecurity Package 2026 — NIS2 amendment (COM(2026) 13) + Cybersecurity Act 2 enter EP preparatory phase; PQC obligation embedded
    weekly-policy
  28. 2026-05-04ENISA expands CVE Numbering Authority root — 4 new CNAs, 7 migrated from MITRE; ~90 European CNAs eligible for transfer
    weekly-policy

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • weekly-policy14
  • weekly-looking-ahead11
  • research1
  • weekly-annual-reports1
  • active-threats1

Source distribution

  • enisa.europa.eu7 (7%)
  • bleepingcomputer.com4 (4%)
  • digital-strategy.ec.europa.eu4 (4%)
  • helpnetsecurity.com4 (4%)
  • securityweek.com4 (4%)
  • advisories.ncsc.nl3 (3%)
  • msrc.microsoft.com3 (3%)
  • edpb.europa.eu2 (2%)
  • other65 (68%)
All cited sources (96)

Entries about EU Cyber Resilience Act (28)

2026-08-16 · view entry permalink →

NOTABLEexploitedNATOB1

2026-W33 looking ahead — items already in motion: a CRA reporting clock at four weeks, standards approval that will not beat it, an exploited flaw with no patch in existence, seven further flaws with no fix coming, and twelve thousand Polish clinics who each owe a notification

Items already in motion at the close of ISO week 2026-W33. Each carries a source and a date; none is a prediction.

  • The Cyber Resilience Act's reporting obligations begin on 11 September 2026 — four weeks out, and the first hard operational clock in the regulation. ETSI's approval procedure for the 17 draft harmonised standards "will run until mid-September to mid-November 2026, depending on the vertical" (ETSI, 2026-08-13), so no presumption-of-conformity route will be available in the covered product categories before the reporting duty starts. The two are independent obligations and the second does not wait for the first.
  • GeoServer's unauthenticated SQL injection has no CVE and no vendor patch, and is being exploited. watchTowr recorded hundreds of exploitation attempts within hours of the 12 August disclosure (SecurityWeek, 2026-08-14). Until OSGeo ships a fix, taking query endpoints off the public internet is the whole remediation — and GeoServer sits under public-sector geoportals and INSPIRE spatial-data services across Europe.
  • Seven further flaws tracked this week have no fix in existence, beyond the GeoServer injection above. ShieldBreak, the published bypass of Microsoft's July fix for the Defender privilege-escalation flaw, is listed as tested on Windows Server 2025 and Windows 11 25H2 with no patch available and no vendor comment at publication (Cyber Kendra, 2026-08-12). Three FreeBSD CAM Target Layer pre-authentication kernel primitives behind TCP/999 were answered with a manpage warning rather than a code fix, and ship enabled by product design on TrueNAS Enterprise high-availability clusters (Calif, 2026-08-06). Three of the five NatJack NAT primitives carry no identifier and no vendor fix, and the Linux change for the one that does is recorded by the researcher as a partial mitigation.
  • Around 12,000 Polish medical facilities each owe their own patients a notification over the MyDr breach, because the data-protection authority has confirmed the duty rests with the healthcare controllers rather than the platform (Gazeta Prawna, 2026-08-13); the facility count is reported at around 12,000 (Notes from Poland, 2026-08-13). MyDr itself has stated it cannot yet say what was taken, so the notifications and the scoping are proceeding in the wrong order.
  • The Dutch Cyberbeveiligingswet registration obligation is live now, not pending. NCSC-NL states the duty applies from the Act's entry into force on 15 August 2026, with registration through the national entity register gated by eHerkenning at level EH2+ or SSOnRijk (NCSC-NL, 2026-08-15); no transition window is described.
  • The Cl0p PTC Windchill extortion wave is between claim and confirmation. A leak-site tracker recorded 44 named victim listings on 12 August including a Swiss and a Dutch organisation, while BleepingComputer counts 43 named through exploitation of the Windchill flaw; two named organisations have since responded — Philips describing a contained single-server event and Shell saying it is investigating — neither attributing its incident to that flaw, and no other named victim has commented (BleepingComputer, 2026-08-14). Organisations running exposed Windchill or FlexPLM instances are in the window where a scoped exposure check and a webshell hunt cost less than waiting for the listing.
  • Swiss federal administrative units have until 1 January 2027 to have built their own information security management system under the federal ordinance this pipeline tracks — four and a half months out, carried forward as a standing date rather than a new development.

Builds on: 2026-08-15/geoserver-jsonarraycontains-unauth-sqli-zeroday-exploited · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-08-10/freebsd-ctl-ha-three-preauth-kernel-rce-primitives-port-999 · 2026-08-10/natjack-nat-trust-assumption-attack-class-two-cves · 2026-08-15/mydr-poland-19-million-records-government-confirmed · 2026-08-15/clop-windchill-philips-shell-first-victim-confirmations

outlook16 Aug 23:59Zmulti-sourceOpen finding ↗

2026-08-16 · view entry permalink →

NOTABLEupdateNATOA1

UPDATE — the Cyber Resilience Act's conformity route entered formal approval this week: ETSI put 17 draft product-category standards out for Public Enquiry, and the procedure runs past the regulation's first reporting deadline

UPDATE · originally covered The European Commission published its first official Cyber Resilience Act application guidance six weeks before the regulation's reporting obligations begin — clarifying which products are in scope, including remote data processing and free and open-source software (2026-08-02)

a prior weekly recorded the European Commission publishing its first official Cyber Resilience Act application guidance — the interpretive half of the problem, answering which products are in scope and what counts as a substantial modification. This week supplies a delta on the other half, the technical route to demonstrating compliance, and it comes with a timetable worth noting.

On 13 August ETSI announced "the availability of the 17 vertical final draft standards developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry", submitted this summer to 41 member organisations across Europe including the national standardisation bodies of the European Economic Area. The purpose is stated plainly: these standards "aim to become Harmonised Standards, giving manufacturers a recognised way to demonstrate compliance with the legislation, the so-called 'presumption of conformity'". The chair of the responsible technical committee frames the gap they fill in a sentence that also explains why their absence matters — "The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how" (ETSI, 2026-08-13), reported independently the following day (Help Net Security, 2026-08-14).

The EN 304 series categories are not consumer-peripheral, which is what makes this a procurement item rather than a compliance-desk one. Alongside browsers, password managers, antivirus software, smart-home virtual assistants, smart-home security products, connected toys and wearables, the drafts cover VPNs, network management systems, SIEM, boot managers, PKI certificate-issuance software, network interfaces, operating systems, routers, modems and switches, virtualization and container platforms, and firewalls — most of a public-sector security stack (ETSI TC CYBER-EUSR open document store, 2026-08-13). The press release itself names only the consumer-facing subset; the full vertical list comes from the draft filenames in ETSI's own open document store, which the release links. The timing is the constraint: ETSI states "The approval procedure will run until mid-September to mid-November 2026, depending on the vertical", and that window opens at or after the CRA's first hard operational date, the reporting obligations beginning on 11 September 2026 that this pipeline already tracks. So for the coming months there is no harmonised standard a supplier can point to, and conformity has to be demonstrated against the regulation's essential requirements directly, or through third-party conformity assessment for the critical categories.

ETSI is pleased to announce the availability of the 17 vertical final draft standards developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry.

The approval procedure will run until mid-September to mid-November 2026, depending on the vertical.

ETSI 2026-08-13

The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how.

Sandra Feliciano, Chair of TC CYBER-EUSR, quoted by ETSI
policy16 Aug 23:59Zmulti-sourceOpen finding ↗

2026-08-09 · view entry permalink →

NOTABLENATOA1

2026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out

Items already in motion at the close of ISO week 2026-W32, each with a source and a date. None of these is a prediction.

Dated obligations.

  • 15 August 2026 — the Netherlands' Cyberbeveiligingswet enters into force, together with the companion critical-entities resilience law, imposing registration, duty-of-care, incident-notification and board-accountability duties on more than 8,000 organisations across 18 sectors, with registration in NCSC-NL's national entity register mandatory from that date (Rijksoverheid, 2026-07-07). Relevant to anyone with Dutch entities, suppliers or public-sector counterparts, whose notification behaviour changes on that date.
  • 11 September 2026 — the Cyber Resilience Act's reporting obligations begin, ahead of the regulation's principal obligations in December 2027. 13 September 2026 — ENISA's consultation on the draft EU Managed Security Services certification scheme closes, two days later; providers delivering services under the EU Cybersecurity Reserve would need that certification within two years of the scheme's entry into force, which makes it a procurement gate rather than a voluntary mark. Both were established in prior weekly coverage and neither date has moved.
  • 2 December 2026 — two new prohibited AI practices apply under the AI Act as amended, and 2 December 2027 / 2 August 2028 are the new application dates for high-risk obligations under Annex III and Annex I respectively, following Regulation (EU) 2026/1744 (EUR-Lex, 2026-07-24). Any readiness plan written against 2 August 2026 for Annex III systems is now diarised to the wrong date.
  • 1 January 2027 — Swiss federal administrative units must have built their ISMS. The Informationssicherheitsverordnung requires the administrative units under its Article 2(1)(c) to build their information-security management system within three years of the ordinance's entry into force, and the ordinance entered into force on 1 January 2024 (Fedlex, ISV SR 128.1). Roughly five months remain. The addressee is the federal administration itself; commentary that presents this as a general critical-infrastructure obligation is reading it more broadly than the text supports.

Disclosure and exploitation clocks.

  • September 2026 — full technical details of the WALLIX Bastion authentication bypass are due. WALLIX states that the reporting researchers intend to publish the complete write-up of the CVSS 4.0 base 10.0 flaw that gives an unauthenticated caller full product-administrator control of the appliance — its credential vault and session recordings included — in September (WALLIX, 2026-07-20). Bastion 12.3.7 and 12.4.1 and later are patched, per the CERT-FR advisory that relayed the bulletin (CERT-FR, 2026-08-06). This is a dated window for remediating quietly, not a current threat.
  • Cl0p's Windchill and FlexPLM listings have still not begun. Research re-checked this week found no leak-site listing for that campaign, leaving affected organisations in the interval between exfiltration and publication — the status a prior weekly recorded, unchanged.

Flaws with no fix coming. Five items from this week's coverage will not be resolved by waiting for a vendor, and each therefore converts into an architecture or lifecycle decision:

  • Tobit TeamDavid — 22 CVEs bounded at "Rollout 524" with no fixed release named, against roughly 12,000 internet-facing instances, and researchers reporting that both they and the coordinating national cyber security centre were left without a vendor response (InfoGuard Labs, 2026-08-07).
  • Flowise — three CVEs assigned days after the vendor announced it is winding down; self-hosted operators own the compensating controls.
  • Zbtlink routers (ENDLESSDOORS) — a factory-shipped root backdoor on twenty models, where the discloser's remediation is device replacement.
  • CPDLC over ATN-B1 — five flaws that are properties of the standard, with CISA recording the remediation category as none-available.
  • Check Point's end-of-support management trains — R80 through R81.10 are listed as affected by this week's unauthenticated management-authentication bypass with no fix on offer.

In development, no date. NCSC UK confirms it is working with international partners on a reference architecture for forensic observability in network appliances, intended to give vendors something concrete to build to (NCSC UK, 2026-07-29). It is not published, and no publication date is stated. Separately, the Metabase SQL-injection zero-day exploited this week still has no CVE identifier assigned, so it will not reach any process that waits for one.

Builds on: 2026-08-09/wallix-bastion-rest-api-unauth-admin-cvss10 · 2026-08-09/teamdavid-tobit-22-cves-unauth-mailbox-takeover-dach · 2026-08-08/flowise-three-cves-vendor-sunset-no-fix-coming · 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-08-08/cpdlc-atn-b1-five-protocol-flaws-no-mitigation-available · 2026-08-05/check-point-cve-2026-18574-management-auth-bypass · 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally

outlook09 Aug 23:45Zmulti-sourceOpen finding ↗

Earlier coverage (25)

2026-08-02NOTABLEexploitedNATOB22026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeksA watch list of items already in motion at the close of ISO week 2026-W31, each with a source and a date — not predictions. Phoenix Contact has committed to CHARX SEC-3xxx firmware 1.9.1 no later than 2026-08-12, with closed-network operation the only control until it ships. IBM's permanent WebSphere fix packs are targeted for 3Q2026, leaving interim APARs as the sole remediation for two CVSS 9.8 pre-auth flaws. Cl0p had not begun listing Windchill victims as of 22 July, placing affected organisations between exfiltration and publication. Three flaws have no fix at all — Langflow's exploited pre-auth RCE, fastjson 1.x, and the Desigo CC V7 family. The Rails Active Storage chain is fully public four weeks ahead of its planned date. And the CRA's reporting obligations begin 2026-09-11.2026-08-02NOTABLENATOA2The European Commission published its first official Cyber Resilience Act application guidance six weeks before the regulation's reporting obligations begin — clarifying which products are in scope, including remote data processing and free and open-source softwareOn 2026-07-27 the European Commission published its first official practical guidance on applying the Cyber Resilience Act, as Communication C(2026) 5252 with a detailed annex carrying 67 worked examples. The guidance is non-binding but is the Commission's authoritative interpretive position on the questions vendors and public-sector procurement teams have been raising: which products fall in scope — remote data processing solutions and free and open-source software among them — what constitutes a substantial modification that restarts conformity obligations, how support periods should be determined, and how the reporting obligations work in practice. It lands six weeks ahead of the CRA's first hard operational clock: the reporting obligations begin on 2026-09-11, more than a year before the regulation's principal obligations apply on 2027-12-11. For this constituency the effect is on the supplier tail, not on the SOC.2026-07-26NOTABLEexploitedNATOA22026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tighteningA justified watch list of items already in motion at the close of 2026-W30 — not predictions. The nginx / NGINX Plus pre-auth heap-overflow CVE-2026-42533 has a working pre-auth RCE demonstrated by its discoverer, with the exploit PoC withheld for roughly 21 days from mid-July disclosure — a public-exploit clock, not a current threat. Oracle's July CPU carries nine unauthenticated CVSS-10.0 Fusion Middleware flaws that NCSC-NL assesses as very likely to see large-scale abuse in the short term. The Windows AD CS "Certighost" flaw CVE-2026-54121 now has a full public PoC that forges a Domain Controller certificate to DCSync, weaponizable against any un-patched AD CS estate. Mitel's unauthenticated MiCollab AWV command-injection flaw (CVSS 9.8) still has no assigned CVE. And two EU compliance clocks tighten: the Dutch NIS2 Cyberbeveiligingswet enters into force 15 August 2026, and the CRA Article 14 24-hour exploited-vulnerability reporting obligation begins 11 September 2026, two days before ENISA's EUMSS certification consultation closes. Each is a concrete, sourced development a Swiss/European defender can act on now.2026-07-26NOTABLENATOA2ENISA moved cyber-assurance into procurement leverage this week — a public consultation on a mandatory EU Managed Security Services certification, and concrete hospital-procurement security guidance under a new Health Action PlanTwo ENISA developments inside 2026-W30 turn soft guidance into procurement leverage relevant to the constituency's supplier tail. ENISA opened a public consultation (2026-07-24, open to 2026-09-13) on the draft EU Managed Security Services (EUMSS) certification scheme under the Cybersecurity Act: mandatory baseline requirements across five domains plus a first "vertical" for Incident Response services, and — the consequential part — any provider delivering services under the EU Cybersecurity Reserve must hold EUMSS certification within two years of the scheme's entry into force, turning voluntary certification into a de facto procurement gate. Separately, ENISA signed a EUR 6 million three-year Health Action Plan Contribution Agreement with the European Commission (2026-07-22) and published its first deliverable — updated procurement guidelines for the cybersecurity of hospitals and healthcare providers, giving buyers concrete language for RFPs and vendor contracts. Neither creates a direct Swiss obligation, but both are trackable now for MSSP-selection and healthcare-procurement criteria, and the EUMSS consultation window closes two days after the CRA Article 14 reporting obligation begins on 11 September 2026.2026-07-19NOTABLEexploitedNATOB22026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks runningA justified watch list of items already in motion at the close of 2026-W29 — not predictions. WordPress "WP2Shell" (CVE-2026-63030/-60137) has public PoC on GitHub with NCSC-NL expecting short-term exploitation; Firefox 152.0.6's two critical flaws (CVE-2026-15718/-15719) carry public exploit code with no confirmed in-the-wild abuse yet. Rapid7 is holding the SharePoint JWT auth-bypass CVE-2026-55040 PoC under a 30-day embargo and its chained RCE half is not scheduled for patch until August, so the July fix is the only current break in that chain. Progress has reserved but withheld a ShareFile Storage Zone Controller CVE, due to publish in roughly two weeks. And two EU regulatory clocks are running: the CRA Article 14 reporting obligation from 11 September 2026 and Germany's KRITIS-Dachgesetz registration window opened 17 July. Each is a concrete, sourced development a Swiss/European defender can act on now.2026-07-19NOTABLENATOB2EU critical-entity and product-resilience regulation reached concrete operator-facing milestones this week — ENISA shipped a CRA readiness self-assessment ahead of the 11 September reporting clock, and Germany's KRITIS-Dachgesetz opened its first CER-Directive registration windowTwo EU critical-infrastructure resilience regulatory milestones landed inside 2026-W29, both moving from text to operator action. ENISA published (2026-07-13) a free SME Cyber Resilience Maturity Assessment Model — a diagnostic self-scoring tool across governance, risk management/secure-by-design, vulnerability management, product lifecycle and skills — explicitly timed ahead of the Cyber Resilience Act's first hard clock: from 11 September 2026, CRA Article 14 requires manufacturers of products with digital elements to issue a CSIRT/ENISA early warning within 24 hours of awareness of an actively exploited vulnerability, a fuller notification within 72 hours, and a final report within 14 days. Separately, Germany's KRITIS-Dachgesetz — the national transposition of the EU Critical Entities Resilience (CER) Directive — opened its first operator-registration window on 17 July 2026, requiring ~1,300 identified critical operators across ten sectors to register on a BBK/BSI platform within three months, starting clocks on a risk analysis (nine months) and a resilience plan (ten months). For a Swiss federal SOC both matter through the constituency's supplier and cross-border tail: EU-market suppliers of connected products to Swiss/European public-sector and CI customers are now on the CRA reporting clock, and Swiss organisations with German CI subsidiaries or CER-equivalent reporting relationships are inside the KRITIS-Dachgesetz scope.2026-07-12NOTABLENATOB2Looking ahead — 2026-W28Items already in motion, not predictions: the Dutch NIS2 Cyberbeveiligingswet enters into force 15 August 2026 (five weeks out) and the EU Cyber Resilience Act's 11 September vulnerability/incident-reporting obligation is ~60 days away; FINMA's post-quantum expectation-setting may harden into a binding circular; the Joomla extension file-upload wave's newest members (RSFiles!/Phoca) are patched but not yet exploited, and prior wave members reached CISA KEV within days; Unit 42 references an Expel write-up of The Gentlemen's suspected EDR-disable zero-day that has not yet published; and the STAC3725 initial-access broker continues weaponising CitrixBleed 2 against un-session-terminated NetScaler.2026-06-29NOTABLELooking ahead — 2026-W26ShinyHunters PeopleSoft notifications are still landing — expect more named European education and public-finance victims. GTIG has notified ~100 organisations (68% higher education) and NAIC is the fresh high-profile case; patch internet-reachable PeopleSoft and hunt /PSEMHUB/ and /PSIGW/HttpListeningConnector.2026-06-29NOTABLEEU Cyber Resilience Act — 75 days to the 11 September vulnerability/incident-reporting obligationCRA Article 28 (conformity-body notification) entered force on 11 June 2026; the next binding milestone — mandatory vulnerability/incident reporting by manufacturers to ENISA's Single Reporting Platform — activates 11 September 2026, now ~75 days out (ENISA SRP).2026-06-22NOTABLELooking ahead — 2026-W25RoguePlanet (CVE-2026-50656) has no patch and a PoC that works on June builds — watch MSRC for an out-of-band fix. Microsoft says a fix is "in development" with no timeline; the researcher warns mitigations are not reliable.2026-06-22HIGHG7 Évian cybersecurity declaration calls PQC an "urgent priority" — and the expected hacktivist DDoS materialised on day onePolicy: the G7 called PQC an "urgent priority" and the predicted NoName057(16) DDoS hit Swiss-border Haute-Savoie sites; the CRA's first reporting obligation lands 11 September. (ANSSI, Cyberattaque.org)2026-06-22NOTABLECRA reporting obligation lands 11 September — ENISA Single Reporting Platform access manual due, dry-runs before go-liveThe first Cyber Resilience Act obligation to bind, from 11 September 2026, requires manufacturers of products with digital elements to report actively exploited vulnerabilities (24-hour early warning + 72-hour notification + final report) and severe incidents through ENISA's Single Reporting Platform (EC Digital …2026-06-14NOTABLELooking ahead — 2026-W24G7 Évian summit, 15–17 June — pre-stage DDoS mitigations now. NCSC-CH's advisory explicitly names Swiss organisations as the hacktivist-DDoS target pool for the summit window (Évian sits on the Swiss border), consistent with the NoName057(16) pattern around past Swiss-adjacent summits.2026-06-14NOTABLEENISA publishes the first EU-wide SBOM Adoption State of Play — consumption lags generationENISA released its end-2025 SBOM adoption survey on 9 June — the first EU-wide empirical baseline (ENISA). The report confirms the CRA is the primary accelerant of SBOM adoption and that organisations are investing in SBOM generation and SDLC/CI-CD integration.2026-06-14NOTABLEGermany's Bundestag opens first reading of the CRA domestic-implementation billDrucksache 21/6134 — "zur Durchführung der Verordnung (EU) 2024/2847" — had its first reading on 11 June, designating Germany's national CRA authorities, notified bodies and enforcement routes, with BSI the anticipated primary market-surveillance authority (Deutscher Bundestag).2026-06-10NOTABLEEU Cyber Resilience Act reaches its first hard deadline — notifying-authority designation due 11 JuneUPDATE (originally covered 2026-W23 weekly): 11 June 2026 is the CRA's first mandatory operational milestone: under Chapter IV, member states must have designated the national authority responsible for notifying conformity-assessment bodies (CABs) for higher-risk product classes (European Commission, 2026-06-10).2026-06-01NOTABLELooking ahead — 2026-W23June 10 — Patch Tuesday: Chaotic Eclipse patches expected; researcher promises a "big surprise" the same day. YellowKey (CVE-2026-45585, BitLocker bypass via WinRE autofstx.exe), GreenPlasma (CTFMON SYSTEM escalation), and MiniPlasma (CVE-2020-17103, cldflt.sys Cloud Filter LPE) remain unpatched as of 7 June.2026-06-01NOTABLECRA June 11 notifying-authority deadline — first hard CRA milestone with ENISA SRP manual and Secure Update Mechanisms advisory published11 June is the Cyber Resilience Act's first mandatory milestone: EU member states must designate the national authority responsible for assessing and notifying conformity assessment bodies (CABs) for Important and Critical product classes (OpenSSF policy blog, 2026-06-03; ENISA SRP page).2026-05-25NOTABLEEU Cyber Resilience Act — 11 June notifying-authority deadline, then September reporting obligationsThe Cyber Resilience Act reaches its first hard operational milestones. By 11 June 2026 (Chapter IV entry into application) member states must designate the national notifying authorities that assess and register conformity-assessment bodies for products with digital elements in the "important" and "critical" …2026-05-11NOTABLELooking ahead — 2026-W20Microsoft Exchange CVE-2026-42897 — Microsoft permanent patch and out-of-band advisory on DEVCORE Pwn2Own three-bug chain pending.2026-05-11NOTABLEEU CRA milestones — 11 June 2026 CAB notification, 11 September 2026 Article 14 reporting obligationsTwo CRA enforcement milestones fall within the next 120 days. Chapter IV provisions on notification of Conformity Assessment Bodies (CABs) become applicable on 11 June 2026 — manufacturers seeking CRA conformity certification for critical digital products will be able to use designated CABs from that date, and …2026-05-11NOTABLEVerizon DBIR 2026 (19th annual edition)Verizon's 19th DBIR is publicly accessible on the Verizon DBIR page; the full PDF release is bound to the 2026-05-19 webinar.2026-05-09NOTABLEENISA expands CVE Root: four new European organisations onboarded as CVE Numbering AuthoritiesOn 2026-05-06 ENISA announced four additional organisations joined the CVE Program as CVE Numbering Authorities (CNAs) under ENISA Root, bringing the total under ENISA oversight to at least eleven (ENISA press release, 2026-05-06).2026-05-04NOTABLEEU Cybersecurity Package 2026 — NIS2 amendment (COM(2026) 13) + Cybersecurity Act 2 enter EP preparatory phase; PQC obligation embeddedThe European Commission's 20 January 2026 cybersecurity package bundles a targeted NIS2 amendment (COM(2026) 13) with a new Cybersecurity Act 2 (CSA2). Public-feedback period closed 22 April 2026 — the package is now in the European Parliament preparatory phase, with political agreement targeted for early 2027.2026-05-04NOTABLEENISA expands CVE Numbering Authority root — 4 new CNAs, 7 migrated from MITRE; ~90 European CNAs eligible for transferENISA announced on 2026-05-06 that four organisations have joined the CVE Programme as CVE Numbering Authorities (CNAs) under ENISA Root, and that seven additional European CNAs have migrated from MITRE Root to ENISA Root (ENISA, 2026-05-06).