An upstream security advisory does not automatically trigger CRA reporting. For manufacturers in scope, the decisive question is whether an actively exploited flaw affects their own product, and if it does, a 24-hour reporting clock can start.
...more