Must manufacturers publicly disclose information about fixed vulnerabilities?
Yes, once a security update has been made available.
Annex I Part II point (4) requires disclosure of information about fixed vulnerabilities, including the vulnerability description, affected products, impact, severity, and clear remediation information. The CRA allows delay only in duly justified cases where publication risk outweighs publication benefit until users have had the possibility to apply the patch.
Annex I Part II point (4)