Skip to main content

How Do I Report an Actively Exploited Vulnerability?

Report immediately

If you suspect a vulnerability in a Brainboxes product is being actively exploited, treat it as a priority and contact us straight away using the contact details below. Do not wait to gather full details first. An initial report with limited information is enough to start our process, our Team will help gather the information we need.

This guide explains how to report a vulnerability in a Brainboxes product that you have evidence is being actively exploited, and what happens once Brainboxes receives your report. It supports our obligations under Article 14 of the EU Cyber Resilience Act (Regulation 2024/2847). See our EU Cyber Resilience Act (CRA) Compliance Statement for background on those obligations and their timelines.

note

Article 14 also covers "severe incidents" affecting Brainboxes as a company (for example, a breach of our own systems). That side of the obligation is something we monitor and identify ourselves, rather than something customers report to us. This guide covers actively exploited product vulnerabilities, which is what you as a customer would report.

What counts as "actively exploited"​

Report through this process if you have evidence or reason to believe that a vulnerability in a Brainboxes product is currently being exploited in the wild, not just that it's theoretically exploitable.

If you've found a vulnerability through independent research or testing with no evidence it has been exploited, please use our guide to reporting a vulnerability instead.

How to report​

Contact us using whichever channel is fastest for you:

  • Email: [email protected]
  • Phone: +44-151-220-2500 and ask to speak to the support team.
  • Encrypted email: use our PGP key if you need to share sensitive technical detail

What we need to know​

Three things are enough for us to start:

  • The affected product model
  • What you're observing that suggests exploitation (e.g. unexpected network traffic, unauthorised access, abnormal device behaviour)
  • Your contact details, so we can follow up

Don't wait to gather anything beyond this. Our reporting deadlines run from the moment we become aware of an exploited vulnerability, so an early report with the minimum is far more useful to us than a complete one that arrives later.

What the support team will ask for​

Once your report is in, the support team will ask you for the following if you haven't already provided them:

  • Firmware or software version(s) in use
  • Any indicators of compromise, logs, or other evidence of exploitation
  • Systems or sites affected, and whether the issue is ongoing

What happens next​

Once we receive your report, we verify it and, if confirmed, follow our internal incident process aligned with CRA Article 14 timelines:

  1. Early warning: notified to the relevant EU authority (ENISA) within 24 hours of Brainboxes becoming aware.
  2. Fuller notification: submitted within 72 hours, including an initial assessment of severity and impact.
  3. Final report: submitted within 14 days of a fix or mitigation becoming available.

We'll also keep you, as the reporter, updated as our investigation progresses, and let you know once a fix or mitigation is available.