Chat with AI and run tools instantly.
The CISA Known Exploited Vulnerabilities (KEV) Catalog is the authoritative U.S. government list of vulnerabilities that are actively being exploited in the wild. Federal agencies are required to remediate KEV entries by their due dates. Search the catalog, look up specific CVEs, find recently added entries, filter by ransomware campaign use, and get summary stats.
Live probe refreshed Sep 14, 2026 · Endpoint host mcp.mcpbundles.com
Domain knowledge for CISA KEV — workflow patterns, data models, and gotchas for your AI agent.
The CISA Known Exploited Vulnerabilities Catalog lists vulnerabilities actively exploited in the wild. Federal agencies must remediate by due dates.
Cwe Breakdown
Get a frequency breakdown of weakness types (CWEs) across all CISA KEV entries. Shows which vulnerability classes are most commonly exploited in the wild.
Due Soon
Find CISA KEV entries with past-due or upcoming federal remediation deadlines. Overdue entries represent federally mandated patches that haven't been addressed — highest compliance liability. Results are sorted by due date ascending (most urgent first).
Lookup
Look up a specific CVE in the CISA Known Exploited Vulnerabilities catalog. Returns full KEV entry details including the required remediation action, federal due date, ransomware campaign association, and affected vendor/product. Returns not_found if the CVE has not been added to the KEV catalog.
Connect CISA KEV to any MCP client in minutes
Opens ChatGPT on the web or desktop and asks it to use the WebMCP tools available here.
You’ll sign in to MCPBundles when your client connects.
https://mcp.mcpbundles.com/bundle/cisa-kevSign in once, then chat here with saved access — one connection to many servers, with a history of what your AI ran.
Chat with AI and run tools instantly.
Browse all toolsProduct Exposure
Get a KEV exposure breakdown for a specific vendor — how many actively exploited vulnerabilities affect each of their products, and which products have ransomware-linked entries.
Ransomware
Get CISA KEV entries that are linked to known ransomware campaigns. These are the highest-priority vulnerabilities — actively exploited AND used by ransomware groups. Optionally filter by vendor. Results sorted newest-first.
Recent
Get the most recently added vulnerabilities to the CISA KEV catalog. Results are sorted newest-first. Use days_back to control the lookback window. Critical for staying on top of newly confirmed exploited vulnerabilities.
Search
Search the CISA KEV catalog by vendor, product, vulnerability name, or keyword. Case-insensitive full-text search across all fields. Use ransomware_only=true to narrow results to ransomware-linked entries. Results are sorted newest-first.
Stats
Get a summary of the CISA Known Exploited Vulnerabilities catalog: total count, catalog version, date released, how many were added in the last 7/30/90 days, how many have known ransomware campaign use, and the top vendors by entry count.
Triage
Check a list of CVEs from a vulnerability scan against the CISA KEV catalog. Returns which CVEs are confirmed actively exploited (in KEV), which are not, and for KEV entries: their federal remediation due date, ransomware flag, and required action. Combine with epss_triage for a full exploit risk picture.
The CISA Known Exploited Vulnerabilities (KEV) Catalog is the authoritative U.S. government list of vulnerabilities that are actively being exploited in the wild. Federal agencies are required to remediate KEV entries by their due dates. Search the catalog, look up specific CVEs, find recently added entries, filter by ransomware campaign use, and get summary stats. It provides 9 tools that AI agents can use through the Model Context Protocol (MCP).
Add the MCPBundles server URL to your MCP client configuration (Claude Desktop, Cursor, VS Code, etc.). The URL format is: https://mcp.mcpbundles.com/bundle/cisa-kev. Authentication is handled automatically.
© 2026 ThinkChain Inc. All rights reserved.
CISA KEV provides 9 tools that can be called by AI agents, along with a SKILL.md that gives your AI agent domain knowledge about when and how to use them.
CISA KEV uses open data APIs — no authentication required.
MCPBundles is an independent platform built on the open Model Context Protocol standard. Not affiliated with Anthropic PBC or Claude.
Other MCP servers in this category from the directory index
OPUSWatch provides API-based solutions for managing operational risk and ensuring regulatory complia...
12 tools