The Investigation Insights – DHS CISA Known Exploited Vulnerabilities Integration returns information on vulnerabilities (CVEs) that have been identified by CISA as meeting the following criteria:
The vulnerability has an assigned Common Vulnerabilities and Exposures (CVE) ID. There is reliable evidence that the vulnerability has been actively exploited in the wild. There is a clear remediation action for the vulnerability, such as a vendor provided update. The integration requires network access to the CISA Known Vulnerability List available here: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Examples
CISA-Vuln Data Overview
- Link to Database: Link out to the NIST vulnerability database.
- Summary: Quick synopsis on the CVE, know if CISA has determined the CVE has been exploited in environments.
- CVE Details: Information about the CVE and the tools that it effects.

