Skip to content

Exploitation watch ​

Two short lists for a daily look: what CISA has just confirmed as exploited, and which CVEs have crossed the EPSS threshold without anything about the vulnerability itself changing. Both carry an available flag that goes false when the underlying data could not be read, so an empty list is never mistaken for a quiet day.

GET /api/v1/kev/recent
GET /api/v1/newly-actionable

For the full EPSS and KEV picture over every tracked CVE, see exploitability; for the signals behind one CVE, see /cve/:id/exploit-signals on the CVE lookup page.

Recent KEV additions ​

GET /api/v1/kev/recent?limit=5

The newest entries in CISA's Known Exploited Vulnerabilities catalogue, with the remediation deadline CISA set and whether the entry is known to be used in ransomware campaigns.

ParameterTypeRequiredDescription
limitintegerNo1 to 20; default 5
json
{
  "success": true,
  "data": {
    "items": [
      {
        "cve": "CVE-2026-88772",
        "dateAdded": "2026-09-27",
        "dueDate": "2026-09-30",
        "vendorProject": "Citrix",
        "product": "NetScaler",
        "name": "Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability",
        "ransomware": false
      }
    ],
    "available": true,
    "catalogVersion": "2026.09.27",
    "fromArchive": false
  },
  "timestamp": "2026-09-28T01:04:48.266Z"
}

available: false means the catalogue could not be read; items is then empty because nothing was checked. fromArchive: true means the live copy had expired and the archived one answered. Cached for fifteen minutes.

Newly actionable by EPSS ​

GET /api/v1/newly-actionable

CVEs whose EPSS score has recently risen past the threshold. The set worth re-triaging even though nothing about each vulnerability changed: the estimate of whether it will be exploited did.

json
{
  "success": true,
  "data": {
    "items": [
      {
        "cve": "CVE-2026-71362",
        "epss": 0.89616,
        "seenAt": "2026-09-25T13:32:13.908Z",
        "title": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation."
      }
    ],
    "count": 41,
    "threshold": 0.5,
    "updatedAt": "2026-09-27T13:30:04.112Z",
    "available": true
  },
  "timestamp": "2026-09-28T01:04:52.101Z"
}

seenAt is when this service first observed the score above the threshold, not when FIRST published it. available: false means the scores have not been computed yet, which is a statement about this API's data and not about the CVEs.