Skip to content
ToolCargo

Docs · Updated 2026-10-03

CISA Known Exploited Vulnerabilities — tool reference

Check recorded known exploitation. Keep source dates and uncertainty attached.

Server URL: https://toolcargo.com/mcp/cisa-kev · Scope: connector:cisa-kev. Activate Site Audit free and connect with ToolCargo OAuth or a scoped API key. No CISA account, provider key, usage form or paid provider. Each successful lookup or page uses one shared-plan call, including cached results.

cisa_kev_lookup

input
{ "cveId": "CVE-2021-44228" }

Use one literal CVE identifier: four year digits and 4–19 sequence digits. Case and surrounding whitespace are normalized; URLs, aliases and lists are rejected. A listed record includes vendor/product, recorded description, date added, CISA’s required-action text, due date, optional ransomware and forensic-triage statuses, CWEs, notes and source links.

not_listed means absent from the indicated validated snapshot. It does not mean safe, not vulnerable or not exploited. Source errors, incomplete catalogues and expired snapshots never become negative membership results. This connector does not assess installed versions, systems or evidence of compromise. Use OSV separately for package/advisory research.

cisa_kev_catalogue

input
{ "vendor": "Apache", "ransomware": "known", "limit": 3 }

Provide at least one literal vendor/product substring, inclusive addedOnOrAfter/addedOnOrBefore calendar date, or ransomware filter. Filters are AND combined; text matching is case insensitive. Dates refer to catalogue addition, not publication, exploitation or remediation. Unknown ransomware filtering selects explicitly recorded Unknown, excluding missing and unfamiliar values.

Each page has 1–20 records (default 10), ordered by date added descending then CVE identifier ascending. Pass nextCursor explicitly with unchanged normalized filters and limit. The cursor binds the projected snapshot fingerprint; a changed snapshot requires restarting. No automatic pagination or user force-refresh. Cursor checks detect malformed/mismatched continuation; cursors are not authorization tokens.

Federal context and honest status fields

dueDate and requiredAction are attributed source metadata with federal remediation context. BOD 26-04, issued June 10, 2026, superseded BOD 22-01 and BOD 19-02. It has defined FCEB scope, exclusions and staged requirements; actual urgency also depends on asset exposure and other factors. ToolCargo does not calculate a personal deadline, give personalized patch instructions or establish legal compliance.

Ransomware status retains the raw string: Known means confirmed campaign use; Unknown means CISA lacks confirmation. Unknown is not No. Missing values become unavailable; unfamiliar values remain unrecognized. Optional forensicTriage retains Yes/No/other/missing and a true/false/null projection. These are source statuses, not instructions to investigate a particular installation.

Source, snapshot and limits

CISA provides the public JSON catalogue under CC0. Third-party linked material retains its own policies and licenses. CISA/DHS logos, seals and endorsement are not included. ToolCargo uses identifying support contact and guarantees neither source availability nor fitness for a particular security decision.

Every result includes source/license/federal-context pointers, catalogVersion, dateReleased, catalogue count, snapshotId, observation/expiry times and cache status. The SHA256 fingerprint identifies the bounded validated projection, not original response bytes or an independently authenticated source signature. Publication and observation dates are separate. This is a current snapshot, not a revision archive.

A shared public database snapshot is reused across instances for at most 30 minutes and remaining valid source max-age minus Age. Source no-store/no-cache/private disables reusable caching; unavailable valid max-age uses a disclosed 30-minute fallback. Body-processing time is subtracted before publication. Refresh ownership and source-directed cooldown are shared; abandoned ownership expires after 60 seconds. Failed refresh does not return stale negatives.

Only the exact CISA HTTPS JSON feed is fetched: 15-second timeout, 4 MB cap, at most 10,000 validated rows, no redirects or retries. The entire count, CVE uniqueness, required field types and calendar dates are validated before caching. No credentials, account cookies, arbitrary URLs, mirrors, code, exploit payloads, installs, scans or followed reference pages.

Source strings are bounded to 16,000 characters before projection. Vendor/product remain intact within that bound for filtering; outward vendor/product text is capped at 200/500, title 500, description 1,000, action and notes 2,000 characters. Up to 20 CWEs and eight unique HTTP(S) pointers per record, with truncation/omission signals. Original optional statuses are capped at 100 characters. Strings and links are inert, untrusted source data; they are never executed or treated as instructions.

Primary sources: CISA KEV catalogue · Current JSON schema · CC0 license · BOD 26-04 · CISA source and update notes.