Live vulnerability intelligence

Know what deserves patch attention today.

PatchBrief turns CISA KEV, MSRC Patch Tuesday, NVD, GitHub advisories, CERT/CC notes, Exploit-DB, and EPSS signals into short briefs with source links, impact context, and the next check to run.

Public-source intelligence. No scanner, no agent, no vendor lock-in.

126 current briefs CISA KEV monitored daily MSRC + CERT/CC intake NVD + GitHub coverage EPSS enrichment Pipeline runs every 24 hours Free tier forever

What you get

One feed for the signals worth triage.

Stop checking advisory portals one by one. PatchBrief normalizes exploited CVEs, vendor advisories, open-source issues, coordinated disclosures, and public exploit signals into records your team can act on.

⚠️

Known Exploited Vulnerabilities

Every CISA KEV addition, reduced to vendor, product, required action, and deadline.

📋

Critical vendor advisories

MSRC Patch Tuesday and NVD critical CVEs are filtered into the fields operators actually use.

🛡️

Open-source advisories

GitHub-reviewed advisories surface dependency risk before it disappears into application backlogs.

Operator check on every brief

Every brief includes a practical check, so the next step is visible before a ticket is opened.

📡

RSS + JSON feed

Subscribe in RSS or pull structured JSON into dashboards, SIEM, Slack, ticketing, or reporting.

📧

Daily and weekly delivery

Start with the weekly digest. Upgrade when daily delivery or watched-vendor alerts matter.

Feed format

Briefs that fit into patch triage.

Each item captures what changed, why it matters, what to check, and where the source claim came from.

Pricing

Start free. Upgrade when the feed becomes workflow.

Use the public feed for discovery. Pay when you need daily delivery, watched-vendor alerts, or supported API access.

Free

$0

forever

The full public feed for discovery and evaluation. No account required.

  • Live public feed (126 current briefs)
  • RSS subscription
  • JSON API preview
  • 365-day public window
  • Filter by type and signal

Team

$49/mo

or $399/year — save 32%

Supported API access for teams routing vulnerability intelligence into internal tools.

  • Everything in Pro
  • Team API access and support
  • 5 team seats
  • Unlimited vendor watchlists
  • CSV export
  • Priority support

All plans include a 14-day refund policy. Full pricing details →

FAQ

Common questions.

Where does the data come from?

CISA KEV, Microsoft Security Update Guide, NVD, GitHub Security Advisories, CERT/CC Vulnerability Notes, Exploit-DB, and FIRST EPSS. PatchBrief summarizes each item and links back to the source.

How is this different from just watching the CISA KEV feed?

CISA KEV confirms known exploitation. PatchBrief adds context, source links, EPSS enrichment, MSRC and NVD coverage, GitHub advisories, CERT/CC notes, and public exploit signals in one feed.

What does the vendor watchlist do?

Pro and Team subscribers can specify the vendors they care about (Cisco, Fortinet, Microsoft, etc.) and receive targeted alerts when a new brief is published for those vendors — instead of reading everything.

Can I integrate this into my SIEM or ticketing system?

Yes. The JSON feed (patchbrief.org/feed.json) is machine-readable and includes brief fields plus source-health metadata. Team subscribers get API onboarding and integration support.

Does PatchBrief scan my environment?

No. PatchBrief is an intel feed based on public sources. It does not scan networks, access systems, or verify exposure. Every brief links to the public source it is based on.

Subscribe

Get the signal without opening another tab.

Subscribe free for weekly highlights. Upgrade to Pro for daily delivery and alerts tied to the vendors you run.