A critical CVE lands in your product. Do you need to report it within 24 hours under the CRA? Not necessarily.
For manufacturers, a vulnerability becomes mandatorily reportable when there is reliable evidence that a malicious actor has actually exploited it. Severity alone does
Delivering #LibericaJDK: supported, @Java standard compatible binaries. Among Top-5 @OpenJDK contributors.

