Must fixed vulnerability information be publicly disclosed once a security update exists?
Yes, with an important timing qualification. Annex I Part II point 4 requires manufacturers, once a security update has been made available, to share and publicly disclose information about fixed vulnerabilities, including affected product identification, impact, severity, and clear remediation information.
The same point allows delayed public disclosure in duly justified cases where the manufacturer considers the security risks of publication to outweigh the security benefits, until users have had the possibility to apply the relevant patch. That makes patch availability, advisory wording, and customer notification timing part of the same transparency workflow.
Annex I Part II point 4 covers public disclosure of fixed vulnerabilities and the justified-delay condition where publication risk outweighs security benefit.