The CISA Known Exploited Vulnerabilities (KEV) Catalog is the authoritative U.S. government list of vulnerabilities that are actively being exploited in the wild. Federal agencies are required to remediate KEV entries by their due dates. Search the catalog, look up specific CVEs, find recently added entries, filter by ransomware campaign use, and get summary stats.
This CISA KEV MCP server is compatible with any MCP client including Claude Desktop, Cursor, and other Model Context Protocol implementations.
Having trouble configuring CISA KEV? Check the available resources below.