Product

The Ostorlab Threat Center Now Supports the EU Vulnerability Database

Ostorlab Threat Center now brings EUVD intelligence alongside NVD data, giving security teams broader vulnerability visibility as they prepare for the EU Cyber Resilience Act.

The Ostorlab Threat Center Now Supports the EU Vulnerability Database

Fri 24 July 2026

A vulnerability database is useful until the one detail you need lives somewhere else. Exploitation status may come from one source, vendor remediation guidance from another, and a coordinated disclosure from a third.

The challenge is not finding more feeds. It is bringing the useful context into one place.

The Ostorlab Threat Center now ingests data from the European Vulnerability Database (EUVD) alongside the U.S. National Vulnerability Database (NVD). This expands the intelligence available to teams monitoring new vulnerabilities and deciding which ones require action.

What EUVD adds

Developed and maintained by ENISA, the EUVD aggregates vulnerability information affecting ICT products and services. Records can include affected products and versions, severity, exploitation status, available patches, and mitigation guidance. The database also highlights critical, actively exploited, and EU-coordinated vulnerabilities.

NVD remains an important source of standardized vulnerability data. EUVD complements it with intelligence and guidance from the European vulnerability ecosystem. Together, the two sources give Threat Center users a broader view of newly disclosed and actively exploited risks.

Why this matters for the Cyber Resilience Act

The timing is important. Under the EU Cyber Resilience Act (CRA), manufacturers of products with digital elements must maintain processes for handling vulnerabilities throughout the product support period.

From September 11, 2026, manufacturers must also report actively exploited vulnerabilities and severe security incidents. An early warning is required within 24 hours of becoming aware, followed by a fuller notification within 72 hours.

Meeting those deadlines begins before a report is filed. Teams need to know that a relevant vulnerability exists, determine whether their products are affected, and prioritize investigation and remediation.

From intelligence to action

Threat Center brings that information into the same workflow teams already use to monitor exposure. They can review a vulnerability, identify potentially affected assets, and launch targeted scans to validate whether the risk is present in their environment.

EUVD support does not make an organization CRA-compliant on its own. It strengthens one of the foundations compliance depends on: timely, reliable vulnerability monitoring connected to real assets and clear follow-up actions.

Open the Ostorlab Threat Center to review current vulnerabilities and validate your exposure.

Table of Contents