Track CISA KEV Exposure by Vendor and Product
Create vendor and product watchlists for actively exploited vulnerabilities in the CISA catalog.

Vendor-focused security reviews often begin with a spreadsheet of strategic technologies: identity providers, VPNs, hypervisors, collaboration platforms, operating systems, and network appliances. The CISA KEV Scraper turns that list into repeatable catalog filters.
Separate vendor and product watchlists
Use vendor filters for broad portfolio coverage:
{"query":"","vendors":["Microsoft","Cisco","Apple"],"sort":"newest","maxResults":500}Use products when a team owns a narrower stack, such as SharePoint, Exchange, or a VPN family. Both filters use case-insensitive containment because CISA naming can include portfolio qualifiers. Review matches before automating tickets; similar product names do not prove that a particular edition or deployment is affected.
The output can support two distinct workflows. Internal vulnerability management joins results to assets and owners. Third-party risk teams compare vendor portfolios with services supplied to the business and ask vendors for remediation evidence when relevant. Neither workflow should label an organization exposed solely because its vendor appears in KEV.
Build a normalized mapping table between CISA names and internal vendor identifiers. Keep the raw vendor and product strings for traceability, then apply aliases downstream. This avoids embedding organization-specific naming logic inside the data collector and makes changes easier to audit.
Schedule each watchlist daily and compare CVE IDs, required actions, due dates, ransomware status, and notes. Route new records to the correct product owner, but retain unmatched entries for inventory review. Quarterly, measure which watchlists produce actionable matches and which contain stale vendors no longer used. That feedback keeps monitoring aligned with the actual technology estate instead of growing into an unowned alert feed.
Frequently asked questions
Are vendor filters exact matches?
No. They use case-insensitive substring matching against CISA's vendor field.
Can several products be monitored together?
Yes. Add multiple product terms and retain the input configuration with each saved Task.
Related
100 free credits, no credit card.
About 30 real searches. Add the MCP to Claude or Cursor in two minutes.