Known Exploited Vulnerabilities
Every CISA KEV addition, reduced to vendor, product, required action, and deadline.
Live vulnerability intelligence
PatchBrief turns CISA KEV, MSRC Patch Tuesday, NVD, GitHub advisories, CERT/CC notes, Exploit-DB, and EPSS signals into short briefs with source links, impact context, and the next check to run.
Public-source intelligence. No scanner, no agent, no vendor lock-in.
What you get
Stop checking advisory portals one by one. PatchBrief normalizes exploited CVEs, vendor advisories, open-source issues, coordinated disclosures, and public exploit signals into records your team can act on.
Every CISA KEV addition, reduced to vendor, product, required action, and deadline.
MSRC Patch Tuesday and NVD critical CVEs are filtered into the fields operators actually use.
GitHub-reviewed advisories surface dependency risk before it disappears into application backlogs.
Every brief includes a practical check, so the next step is visible before a ticket is opened.
Subscribe in RSS or pull structured JSON into dashboards, SIEM, Slack, ticketing, or reporting.
Start with the weekly digest. Upgrade when daily delivery or watched-vendor alerts matter.
Feed format
Each item captures what changed, why it matters, what to check, and where the source claim came from.
Confirm Splunk Enterprise is patched. Apply mitigations per vendor instructions and CISA BOD 26-04 guidance. Remediation deadline: Jun 21, 2026.
Verify Chrome/Chromium is updated across managed endpoints. Check unmanaged devices and browser deployment policy.
Apply the latest Firefox update across all managed systems. Verify auto-update is enabled for unmanaged devices.
Pricing
Use the public feed for discovery. Pay when you need daily delivery, watched-vendor alerts, or supported API access.
Free
$0
forever
The full public feed for discovery and evaluation. No account required.
Pro
$9/mo
or $79/year — save 27%
Daily delivery and watched-vendor alerts for operators who cannot babysit every source.
Team
$49/mo
or $399/year — save 32%
Supported API access for teams routing vulnerability intelligence into internal tools.
All plans include a 14-day refund policy. Full pricing details →
FAQ
CISA KEV, Microsoft Security Update Guide, NVD, GitHub Security Advisories, CERT/CC Vulnerability Notes, Exploit-DB, and FIRST EPSS. PatchBrief summarizes each item and links back to the source.
CISA KEV confirms known exploitation. PatchBrief adds context, source links, EPSS enrichment, MSRC and NVD coverage, GitHub advisories, CERT/CC notes, and public exploit signals in one feed.
Pro and Team subscribers can specify the vendors they care about (Cisco, Fortinet, Microsoft, etc.) and receive targeted alerts when a new brief is published for those vendors — instead of reading everything.
Yes. The JSON feed (patchbrief.org/feed.json) is machine-readable and includes brief fields plus source-health metadata. Team subscribers get API onboarding and integration support.
No. PatchBrief is an intel feed based on public sources. It does not scan networks, access systems, or verify exposure. Every brief links to the public source it is based on.
Subscribe
Subscribe free for weekly highlights. Upgrade to Pro for daily delivery and alerts tied to the vendors you run.
The highest-signal items from the week, delivered Monday morning.
Get daily alerts for the vendors and products you care about.
Get Pro →