Currently free during beta - premium features coming soon. Subscribe now to lock in early access.
All Changes

EU Regulatory Changes

1668 changes tracked across 24 compliance frameworks including DORA, NIS2, GDPR, EU AI Act, Cyber Resilience Act, and more.

All DORA NIS2 GDPR CSRD MaRisk ISO27001 EU_AI_ACT CRA DSA DMA eIDAS2 SOC2 PCI_DSS HIPAA ISO42001 AMLD6 PSD3 DATA_ACT GPSR CER EUDR CVE BREACH AI_SAFETY
CVE-2026-8181 (CVSS 9.8) — The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)...
CVE-2026-6271 (CVSS 9.8) — The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all vers...
CVE-2026-6510 (CVSS 9.8) — The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing ...
CVE-2026-6512 (CVSS 9.1) — The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versi...
CVE-2025-11024 (CVSS 9.8) — Improper neutralization of special elements used in an SQL command ('SQL injection') vuln...
CVE-2026-2347 (CVSS 9.8) — Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software...
CVE-2026-41615 (CVSS 9.6) — Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator all...
CVE-2026-8634 (CVSS 9.1) — Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allo...
CVE-2026-5229 (CVSS 9.8) — The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up...
KEV: CVE-2026-20182 — Cisco Catalyst SD-WAN (Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability)
KEV: CVE-2026-42208 — BerriAI LiteLLM (BerriAI LiteLLM SQL Injection Vulnerability)
KEV: CVE-2026-6973 — Ivanti Endpoint Manager Mobile (EPMM) (Ivanti Endpoint Manager Mobile (EPMM) Improper Input Vali...
KEV: CVE-2026-0300 — Palo Alto Networks PAN-OS (Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability)
Breach: Abrigo (711,099 accounts) — Email addresses, Employers, Job titles
CELEX:32024R1991R(05)
This corrigendum, published on 13 May 2026, corrects technical errors in the original Digital Operational Resilience Act (DORA) Delegated Regulation 2024/1991, which specifies criteria for classify...
Read analysis →
Opinion 13/2026 on the draft decision of the Office of the Data Protection Ombudsman (FI SA) regarding the approval o...
The European Data Protection Board has published Opinion 13/2026, endorsing a draft decision by the Finnish Data Protection Ombudsman to approve accreditation requirements for certification bodies ...
Read analysis →
CELEX:32022R2065R(10)
This is a corrigendum to the Digital Services Act (DSA), specifically correcting an error in the original Regulation (EU) 2022/2065. The correction addresses a technical mistake in Article 24(3) co...
Read analysis →
CELEX:32024R2145R(01)
This corrigendum, published on 11 May 2026, corrects technical errors in the original Digital Operational Resilience Act (DORA) Delegated Regulation 2024/2145. The changes are limited to fixing ina...
Read analysis →
Press release - Europeans celebrate unity, values and democracy on Europe Day 2026
On 8 May 2026, the European Parliament published a press release marking Europe Day 2026, which reaffirms the EU’s commitment to unity, democratic values, and digital sovereignty. While the release...
Read analysis →
Press release - AI Act: deal on simplification measures, ban on “nudifier” apps
On 7 May 2026, the European Parliament published a press release announcing a political agreement on simplification measures to the EU AI Act, alongside a specific ban on so-called “nudifier” appli...
Read analysis →