CISA KEV + EPSS Vulnerability Intelligence Tracker avatar

CISA KEV + EPSS Vulnerability Intelligence Tracker

Pricing

from $50.00 / 1,000 enriched cves

Go to Apify Store
CISA KEV + EPSS Vulnerability Intelligence Tracker

CISA KEV + EPSS Vulnerability Intelligence Tracker

Track CISA Known Exploited Vulnerabilities (KEV) with EPSS scores — CVE, vendor, product, date added, due date and required action — as clean JSON for security teams and agents.

Pricing

from $50.00 / 1,000 enriched cves

Rating

0.0

(0)

Developer

NexGenData

NexGenData

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

a day ago

Last modified

Categories

Share

A focused utility for developers and agents.

📊 Sample Output

1 real rows delivered by CISA KEV + EPSS Vulnerability Intelligence Tracker — run 7od9kF17ZVZqm8C9n on build 0.0.7

cveIDkev_added_datedue_dateepss_scoreepss_percentileepss_date
CVE-2026-200792026-09-092026-09-120.88180.997652026-09-24

Real rows from run 7od9kF17ZVZqm8C9n on build 0.0.7 (2026-09-25), unedited apart from masked emails/phones and shortened long text; fields the source does not publish are empty.

⚙️ Sample inputs

This is the Store example input — the same input Apify's automated check runs — so it is proven to return rows on the current build. Paste it into the input form, or send it through the API, CLI or a schedule:

{
"min_epss_score": "0.5",
"days_back": 30,
"max_cves": 100
}

🔧 Input reference

FieldTypeDefaultWhat it does
vendor_filterstring""Substring match on the CISA KEV vendorProject field (case-insensitive). Examples: 'microsoft', 'cisco', 'fortinet'. Leave empty to include every vendor in the KEV catalog window.
min_epss_scorestring"0.5"Filter CVEs whose EPSS exploit-probability score is below this threshold (parsed as a float in [0,1]). EPSS ≥ 0.5 typically flags vulnerabilities with elevated near-term exploitat…
days_backinteger30How many days back from today to include CISA KEV catalog additions. Default 30 captures the freshest entries (typical triage window). Max 365.
max_cvesinteger100Hard cap on the number of CVEs to enrich and push to the dataset (KEV records are sorted newest-first before the cap). Each enriched CVE is a billable record. Range 1-2000.

🧾 JSON sample record

One real record from run 7od9kF17ZVZqm8C9n (emails/phones masked, long text shortened):

{
"cveID": "CVE-2026-20079",
"vendor": "Cisco",
"product": "Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management",
"vulnerability_name": "Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability",
"kev_added_date": "2026-09-09",
"due_date": "2026-09-12",
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.",
"nvd_description": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. \r\n\r\nThis vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. ",
"epss_score": 0.8818,
"epss_percentile": 0.99765,
"epss_date": "2026-09-24",
"cvss_v3_base": 10,
"cvss_severity": "CRITICAL",
"cwe_ids": [
"CWE-288"
],
"affected_cpes": [
"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:cisco:secure_firewall_management_center:7.0.4:*:*:*:*:*:*:*",
"…"
],
"known_ransomware_use": false,
"cwes_in_kev": [
"CWE-288"
],
"notes": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-20079",
"sources": {
"kev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"epss": "https://www.first.org/epss",
"nvd": "https://nvd.nist.gov/vuln/detail/CVE-2026-20079"
}
}

💰 Pricing

EventPrice (USD)When it is charged
Actor Start (apify-actor-start)$0.005Charged when the Actor starts running. Number of events charged depends on Actor memory (one event per GB, minimum one event).
Enriched CVE (cve-enriched)$0.05Per CVE enriched with KEV + EPSS + NVD CVSS + affected products

Pay-per-event: you pay only for what the run delivers. A run that delivers nothing bills no result events (only the actor-start event, when the actor defines one). Example: a run that delivers 100 results costs 100 × $0.05 = $5.00 plus the start fee.

More from the NexGenData US government, courts & regulators family:

46 more in this family on the NexGenData Store page.

⏰ Schedule it

Run on a schedule (0 8 * * 1) to monitor changes over time — an always-on CVE watch.

📊 What you get

Clean JSON output (20 fields):

  • cveID — Cve ID
  • vendor — Vendor
  • product — Product
  • vulnerability_name — Vulnerability name
  • kev_added_date — Kev added date
  • due_date — Due date
  • required_action — Required action
  • short_description — Short description

Pricing: $0.05 per CVE (Pay-Per-Event) — about 20 per $1. Actor start fee $0.005 per run. Live prices are in the Pricing table below.

🤖 Use with AI agents

Point Claude, the OpenAI Agents SDK, an n8n flow or any MCP-aware client at it.

Sample agent prompt:

Run CISA KEV + EPSS Vulnerability Intelligence Tracker on my input and return the structured results.

Agentic payments (x402): Supports agentic payment via x402 — call this actor with USDC, no API key required.

SSL Checker · DMARC Auditor · Domain Security Posture · CVE Monitor · Dependency Advisories · Chrome Extension Analyzer

This actor is currently private — treated and ready for review.

A NexGenData utility actor.