Skip to content
ToolCargo

CISA Known Exploited Vulnerabilities

Live

Check CISA's recorded known exploitation by CVE.

Check an exact CVE against CISA's Known Exploited Vulnerabilities catalogue, or research filtered vendor and product additions. Keep recorded exploitation, ransomware uncertainty and federal remediation context attached to a dated source snapshot.

Connect / 2 tools

Server URL

streamable http
https://toolcargo.com/mcp/cisa-kev

Claude Code

terminal
claude mcp add --transport http --scope user toolcargo-cisa-kev https://toolcargo.com/mcp/cisa-kev \
  --header "Authorization: Bearer YOUR_API_KEY"

Create a key in your dashboard. Other clients: setup guides.

What it helps you do

  • Recorded known-exploitation lookup
  • Filtered vendor and product research
  • Dated federal source context

Built for: Developer and security research agents reviewing public vulnerability records.

Example requests

Add recorded exploitation context to an advisory

“Look up CVE-2021-44228 in CISA KEV, then research Apache records with known ransomware campaign use. Inspect two explicit pages with the same snapshot and report source dates and federal due-date context. Do not treat absence as safety or give personalized patch instructions.”

Source-linked recorded exploitation context alongside general advisory research.

Explore useful agent workflows ↗

Tools

ToolWhat it doesAccess
cisa_kev_lookup
Look up CISA known exploitation by CVE
Look up one exact CVE in CISA's validated Known Exploited Vulnerabilities snapshot. Returns dated membership, bounded source descriptions/actions, federal due-date context, ransomware/forensic-triage status and provenance. Not listed does not mean safe or not exploited. One shared-plan call.Read-only
cisa_kev_catalogue
Research a filtered CISA KEV page
Filter CISA KEV by literal vendor/product, inclusive added dates or known/unknown ransomware status. At least one filter; AND combined. Up to 20 records with explicit snapshot-bound nextCursor, newest added first. No automatic paging, exploit code, scanning or personalized patch/compliance decisions. One shared-plan call.Read-only

Requirements

  • • A ToolCargo account with Site Audit activated (free). No CISA account, API key, usage form or paid provider.

Limitations

  • • CISA supplies a public JSON catalogue under CC0. Linked third-party content has separate terms. CISA/DHS logos, seals and endorsement are not included; upstream availability is not guaranteed.
  • • A validated snapshot can be cached across instances for at most 30 minutes and remaining source max-age minus Age; fallback 30 minutes when valid max-age is unavailable. Source no-store/no-cache prevents reusable caching. Snapshot SHA256 identifies the bounded projection, not original source bytes.
  • • Not listed means absent from that validated catalogue snapshot only; it does not prove no exploitation, vulnerability or risk. Failed or expired source reads never produce a stale negative.
  • • Due dates and required actions retain federal remediation context under BOD 26-04, which superseded BOD 22-01. No asset assessment, legal/compliance guarantee or personalized patch instructions.
  • • Ransomware Unknown means lacks confirmation, not no. Optional ransomware and forensic-triage strings retain missing/unrecognized states.
  • • At least one literal vendor/product, added-date or ransomware filter; up to 20 records per explicit snapshot-bound cursor page. Pages cannot mix snapshots. Text and reference links are bounded with truncation signals.
  • • One fixed HTTPS feed, 4 MB/15-second transport bound, at most 10,000 validated records and shared refresh lease/cooldown. No redirects, retries, mirrors, user data, code, exploits, scanning, installs or followed links. Successful cache hits also use one shared-plan call.

Supported clients

“Tested” means we connected that client to this endpoint and ran a tool call ourselves. Recorded client-specific tests currently cover Site Audit. Other connectors use the documented setup until tested in that client.

Claude CodeAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
Claude (claude.ai)OAuth sign-inDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
CursorAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
VS Code (Copilot agent mode)API key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
ChatGPT (developer mode)OAuth sign-inDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
MCP InspectorAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.

Practical workflows

Pricing

Included with Site Audit. Each successful exact lookup or filtered page uses one shared-plan call.

Free

$0

Try hosted tools with a shared monthly allowance.

50 shared calls/month

Pro

$12/mo

Proposed larger shared allowance; see checkout status on the pricing page.

2,000 shared calls/month

Proposed test price. See the pricing page for checkout status.

Full pricing and billing details