Pulls the CISA Known Exploited Vulnerabilities catalog into your LLM workflow so you can query CVEs that are actively being exploited in the wild and check BOD 22-01 remediation deadlines for federal and critical infrastructure environments. You get three main operations: query the KEV catalog by CVE or vendor, check whether a vulnerability has a compliance deadline, and export KEV data as SBOM artifacts. Useful when you're triaging vulnerabilities and need to prioritize based on real-world exploitation rather than just CVSS scores, or when you're automating compliance checks against the federal mandate. The EPSS overlay mentioned in the description suggests risk scoring integration, though the docs focus primarily on the core KEV lookup and deadline tracking features.
mcp-name: io.github.CSOAI-ORG/cisa-kev-mcp
CISA Known Exploited Vulnerabilities MCP
Buy Starter — £29/mo
Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.
Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.
CISA Known Exploited Vulnerabilities MCP. BOD 22-01 + EPSS overlay. MIT
# Install via pip
pip install cisa_kev_mcp
# Or install via Smithery
npx -y @smithery/cli@latest install cisa-kev-mcp --client claude
This MCP server is built with EU AI Act compliance built-in:
Free: 10 calls/day. No API key required.
Pro £79/mo: unlimited + signed attestations. Subscribe
Enterprise £1,499/mo: white-label + on-premise + SLA. hello@meok.ai
✅ Article 9 — Risk Management System
✅ Article 13 — Transparency & Instructions for Use
✅ Article 15 — Bias Detection & Testing
✅ Article 26 — FRIA Support (where applicable)
✅ Article 50 — AI Content Watermarking (where applicable)
Need help getting compliant? Book a free 15-min diagnostic →
Need custom development, SLA guarantees, or white-label deployment?
View Pricing → | Contact Sales →
This server is part of the MEOK AI Labs ecosystem — 300+ MCP servers for sovereign AI governance.
| Domain | Purpose |
|---|---|
| councilof.ai | EU AI Act compliance marketplace |
| safetyof.ai | AI safety & monitoring |
| meok.ai | Sovereign AI platform |
| cobolbridge.ai | Legacy modernization |
MIT © CSOAI-ORG
Built with 💜 by MEOK AI Labs · UK Companies House 16939677
| Tier | Price | What you get | Stripe |
|---|---|---|---|
| Smoke test | £1 | Signed sample MCP-Hardening report + Article 50 PDF | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
| Quick Kit | £9 | EU AI Act Article 50 implementation guide (C2PA + EU-Icon) | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
| Founder Call | £29 | 30-min 1-on-1 with the founder | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
Refundable. UK Stripe — VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.
Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:
{
"mcpServers": {
"cisa-kev-mcp": {
"command": "uvx",
"args": ["cisa-kev-mcp"]
}
}
}
Or: pip install cisa-kev-mcp then run the cisa-kev-mcp command (stdio transport).
Once configured, ask your assistant, for example:
query_kev_catalog to …"check_remediation_deadline to …"export_kev_sbom to …"