Agent Tools / MCP install guides / CVE Exploit Status, EPSS and Patch Priority Lookup
Answer Guide

CVE Exploit Status, EPSS and Patch Priority Lookup

CVE Risk Check answers four short questions about a CVE id: is it exploited, how likely is exploitation, which ids come first, and what CISA added lately. Last checked 2026-10-01.

is CVE-2021-44228 actively exploited

CVE Risk Check marks a CVE as exploited when the CISA Known Exploited Vulnerabilities catalog lists it.

The answer also gives CISA's due date and required action, the CVSS score and severity from the National Vulnerability Database, and the dates of both records. Tool: check_cve on https://cve.openkrill.app/mcp.

CVE EPSS score exploitation probability

The EPSS score is FIRST's modelled chance that a CVE is exploited in the next 30 days, and check_cve returns it with the date it was read.

A CVE that CISA does not list is marked likely when its EPSS score is 0.1 or more, and routine below that. If EPSS could not be read, the priority is unknown. Tool: check_cve on https://cve.openkrill.app/mcp.

which CVEs to patch first

check_cves ranks up to 10 CVE ids with the most urgent first, using the CISA exploited list and the EPSS score.

It returns the priority, CVSS score and EPSS score of each id and a count per priority. An id the National Vulnerability Database could not be asked about is marked deferred, not safe. Tool: check_cves on https://cve.openkrill.app/mcp.

CISA known exploited vulnerabilities added this month

list_recent_kev lists the CVEs CISA added to its Known Exploited Vulnerabilities catalog in the last 90 days or fewer, newest first.

You can filter by a product word. Each row has CISA's name for the flaw, the date added, CISA's due date and the CVSS score. The catalog lists exploited flaws only, not every serious CVE. Tool: list_recent_kev on https://cve.openkrill.app/mcp.

Run it yourself

This page does not return live data. Call the tool on the server to get it. The server is CVE Risk Check at https://cve.openkrill.app/mcp, with no key. Install steps: ChatGPT, Claude, Cursor, Pi. A call to check_cve was posted to the live server on 2026-10-01, and the install pages show it. The full tool list is in the MCP install guides directory.

Source: the CVE Risk Check plugin listing in this repository and a live tools/call on 2026-10-01. Last checked 2026-10-01. These answers are reviewed again every 1 to 3 months.